This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Plzz help me with Root kit agent ODG , AGAIN

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Sorry if I post this topic in wrong place, or it is solved problem, but, I read much posts about removing a trojan, Win32 rootkit Agent ODG, I did as they told but it is'nt removed. I don't know why I restoređ whole partition from image of C drive , and I reinstalled my system, but when I use Nod 32 smart security 4, I detect it's again, and can't clean ? always "operating memory : win32/rootkit.agent.ODG " plzzz help me :(( . Thanks Could you plzz contact with me via YM, o0o_august_peridot_o0o. Thank you very much
Hi

Please do the following:

NEXT

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries



NEXT


We Need to check for Rootkits with RootRepeal
  • Download RootRepeal from the following location and save it to your desktop.
  • Extract RootRepeal.exe from the archive.
  • Open [external image: Posted Image] on your desktop.
  • Click the [external image: Posted Image] tab.
  • Click the [external image: Posted Image] button.
  • Check all seven boxes: [external image: Posted Image]
  • Push Ok
  • Check the box for your main system drive (Usually C:), and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.
Oh, thank you very much to reply my post. Uhm, I scanned by apps from you, but Gmer, when I use it, it create the "system dump " and then blue screen. I must restart computer. So, i just have the reports from dds and Root repeal, not Gmer. dds.txt———————————————————————————————————————————————————————————– DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 10:21:34.51 on Tue 08/25/2009 Internet Explorer: 8.0.6001.18813 Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.3068.1243 [GMT 7:00] SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\STacSV.exe C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\rundll32.exe C:\Windows\system32\Hpservice.exe C:\Windows\system32\vfsFPService.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\SWSetup\DigitalPersona\Bin\DpHostW.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\SWSetup\DigitalPersona\Bin\DpAgent.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\IDT\WDM\sttray.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\System32\rundll32.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files\HP\QuickPlay\QPService.exe C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe D:\Install\Razer\Copperhead\razerhid.exe C:\Program Files\Windows Sidebar\sidebar.exe D:\Install\UniKey 4.0.8 Final\UniKey.exe C:\Program Files\Windows Sidebar\sidebar.exe D:\Install\Razer\Copperhead\razerofa.exe C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\aestsrv.exe C:\Windows\system32\agrsmsvc.exe C:\Windows\system32\svchost.exe -k bthsvcs D:\Install\ESET Smart Security 4\ekrn.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\DllHost.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe D:\Install\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe D:\Install\Internet Download Manager 5.17\IDMan.exe D:\Install\Internet Download Manager 5.17\IEMonitor.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe D:\Install\Spyware Doctor\pctsAuxs.exe D:\Install\Spyware Doctor\pctsSvc.exe D:\Install\Spyware Doctor\pctsTray.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\SearchProtocolHost.exe C:\Users\o0 Virgo 0o\Desktop\dds.EXE ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com.vn/ BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - d:\install\internet download manager 5.17\IDMIECC.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [UniKey] d:\install\unikey 4.0.8 final\UniKey.exe mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [DpAgent] c:\swsetup\digitalpersona\bin\dpagent.exe mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe" mRun: [OnScreenDisplay] c:\program files\hewlett-packard\hp quicktouch\HPKBDAPP.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_05\bin\jusched.exe" mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [Copperhead] d:\install\razer\copperhead\razerhid.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Download all links with IDM - d:\install\internet download manager 5.17\IEGetAll.htm IE: Download FLV video content with IDM - d:\install\internet download manager 5.17\IEGetVL.htm IE: Download with IDM - d:\install\internet download manager 5.17\IEExt.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Send image to &Bluetooth Device… - c:\swsetup\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - c:\swsetup\widcomm\bluetooth software\btsendto_ie.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\swsetup\widcomm\bluetooth software\btsendto_ie.htm IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab TCP: {A0D5BE24-2A69-4825-B6B4-232AB7C22CE6} = 203.113.131.1,203.113.131.2 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL LSA: Notification Packages = scecli DPPWDFLT ================= FIREFOX =================== FF - ProfilePath - c:\users\o0virg~1\appdata\roaming\mozilla\firefox\profiles\hbza7uts.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.vn/ FF - component: c:\users\o0 virgo 0o\appdata\roaming\idm\idmmzcc3\components\idmmzcc.dll FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll FF - plugin: d:\install\k-lite mega codec pack 5.05\real\browser\plugins\nppl3260.dll FF - plugin: d:\install\k-lite mega codec pack 5.05\real\browser\plugins\nprpjplug.dll FF - plugin: d:\install\picasa3\npPicasa3.dll —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-8-21 130936] R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-2-6 106208] R2 {22D78859-9CE9-4B77-BF18-AC83E81A9263};{22D78859-9CE9-4B77-BF18-AC83E81A9263};c:\program files\hp\quickplay\000.fcl [2009-8-20 39408] R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_030ac640\AEstSrv.exe [2009-8-20 73728] R2 ekrn;ESET Service;d:\install\eset smart security 4\ekrn.exe [2009-2-6 727720] R2 epfwwfp;epfwwfp;c:\windows\system32\drivers\epfwwfp.sys [2009-2-6 38240] R2 hpsrv;HP Service;c:\windows\system32\hpservice.exe [2008-3-19 19456] R2 MBAMService;MBAMService;d:\install\malwarebytes' anti-malware\mbamservice.exe [2009-8-21 232720] R2 sdAuxService;PC Tools Auxiliary Service;d:\install\spyware doctor\pctsAuxs.exe [2009-8-21 348752] R2 vfsFPService;Validity Fingerprint Service;c:\windows\system32\vfsFPService.exe [2008-3-27 595248] R3 AVerBDA6x;AVerBDA6x service;c:\windows\system32\drivers\AVerBDA716x.sys [2009-8-20 934912] R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2009-8-20 193840] R3 enecir;ENE CIR Receiver;c:\windows\system32\drivers\enecir.sys [2008-10-28 52736] R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2008-10-28 81296] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-8-21 19096] R3 NETw5v32;Intel® Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\system32\drivers\NETw5v32.sys [2008-10-28 3658752] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-10-28 43552] R3 vfs101x;vfs101x;c:\windows\system32\drivers\vfs101x.sys [2008-3-27 40752] S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe [2006-11-2 9216] S3 UsbFltr;Razer Copperhead Driver;c:\windows\system32\drivers\copperhd.sys [2009-8-21 11596] =============== Created Last 30 ================ 2009-08-24 01:02 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf 2009-08-21 03:20 5,702 a—h— c:\windows\nod32restoretemdono.reg 2009-08-21 03:20 568 a—h— c:\windows\nod32fixtemdono.reg 2009-08-21 03:15 –d—– c:\users\o0virg~1\appdata\roaming\ESET 2009-08-21 03:14 –d—– c:\programdata\ESET 2009-08-21 01:09 –d—– c:\users\o0virg~1\appdata\roaming\Desktopicon 2009-08-21 00:52 –d—– c:\users\o0virg~1\appdata\roaming\Malwarebytes 2009-08-21 00:52 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-21 00:52 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-08-21 00:52 –d—– c:\programdata\Malwarebytes 2009-08-21 00:52 –d—– c:\progra~2\Malwarebytes 2009-08-21 00:34 51,355 a——- c:\windows\system32\muzika.xm 2009-08-21 00:29 159,600 a——- c:\windows\system32\drivers\pctgntdi.sys 2009-08-21 00:29 130,936 a——- c:\windows\system32\drivers\PCTCore.sys 2009-08-21 00:29 73,840 a——- c:\windows\system32\drivers\PCTAppEvent.sys 2009-08-21 00:28 64,392 a——- c:\windows\system32\drivers\pctplsg.sys 2009-08-21 00:28 –d—– c:\program files\common files\PC Tools 2009-08-21 00:28 –d—– c:\users\o0virg~1\appdata\roaming\PC Tools 2009-08-21 00:28 –d—– c:\programdata\PC Tools 2009-08-21 00:28 –d—– c:\progra~2\PC Tools 2009-08-21 00:09 14,592 a——- c:\windows\system32\drivers\USBICP.sys 2009-08-21 00:09 69,632 a——- c:\windows\system32\copperhd.cpl 2009-08-21 00:09 11,596 a——- c:\windows\system32\drivers\copperhd.sys 2009-08-20 23:58 –d—– c:\programdata\FLEXnet 2009-08-20 19:17 –d—– c:\users\o0 virgo 0o\Bluetooth Software 2009-08-20 19:17 80,936 a——- c:\windows\system32\drivers\btwavdt.sys 2009-08-20 19:17 80,424 a——- c:\windows\system32\drivers\btwaudio.sys 2009-08-20 19:17 16,168 a——- c:\windows\system32\drivers\btwrchid.sys 2009-08-20 19:17 233,472 a——- c:\windows\system32\BtwRSupport.dll 2009-08-20 19:17 –d—– c:\windows\system32\es-MX 2009-08-20 19:17 –d—– c:\windows\system32\es-AR 2009-08-20 19:15 12 a——- c:\windows\bthservsdp.dat 2009-08-20 19:12 –d—– c:\users\o0virg~1\appdata\roaming\DigitalPersona 2009-08-20 18:59 –d—– c:\programdata\CyberLink 2009-08-20 18:58 1,233,920 a——- c:\windows\system32\msxml4.dll 2009-08-20 18:58 82,432 a——- c:\windows\system32\msxml4r.dll 2009-08-20 18:58 44,544 a——- c:\windows\system32\msxml4a.dll 2009-08-20 18:58 1,060,864 ——– c:\windows\system32\MFC71.dll 2009-08-20 18:58 1,047,552 ——– c:\windows\system32\MFC71u.dll 2009-08-20 18:58 499,712 ——– c:\windows\system32\msvcp71.dll 2009-08-20 18:58 348,160 ——– c:\windows\system32\msvcr71.dll 2009-08-20 18:58 89,088 ——– c:\windows\system32\atl71.dll 2009-08-20 18:57 1,560,576 a——- c:\windows\system32\BttnCmns_64.dll 2009-08-20 18:57 1,560,576 a——- c:\windows\system32\BttnCmns.dll 2009-08-20 18:57 1,419,232 a——- c:\windows\system32\drivers\wdfcoinstaller01005.dll 2009-08-20 18:57 987,136 a——- c:\windows\system32\BttnCmn.dll 2009-08-20 18:57 16,768 a——- c:\windows\system32\drivers\HpqKbFiltr.sys 2009-08-20 18:57 –d—– c:\program files\common files\muvee Technologies 2009-08-20 18:56 –d—– c:\programdata\muvee Technologies 2009-08-20 18:53 –d—– c:\program files\HP 2009-08-20 18:52 –d—– c:\users\o0virg~1\appdata\roaming\Macrovision 2009-08-20 18:51 –d—– c:\windows\system32\tr 2009-08-20 18:51 –d—– c:\windows\system32\ru 2009-08-20 18:51 –d—– c:\windows\system32\ko 2009-08-20 18:51 –d—– c:\windows\system32\ja 2009-08-20 18:51 –d—– c:\windows\system32\it 2009-08-20 18:51 –d—– c:\windows\system32\fr 2009-08-20 18:51 –d—– c:\windows\system32\es 2009-08-20 18:51 –d—– c:\windows\system32\de 2009-08-20 18:51 –d—– c:\windows\DPDrv 2009-08-20 18:51 –d—– c:\programdata\Macrovision 2009-08-20 18:49 –d—– c:\programdata\NVIDIA 2009-08-20 18:49 28,409 a——- c:\programdata\nvModes.dat 2009-08-20 18:49 28,409 a——- c:\progra~2\nvModes.dat 2009-08-20 18:45 1,079,840 a——- c:\windows\system32\nvcpluir.dll 2009-08-20 18:45 768,544 a——- c:\windows\system32\nvcplui.exe 2009-08-20 18:45 420,384 a——- c:\windows\system32\nvcpl.cpl 2009-08-20 18:45 313,888 a——- c:\windows\system32\nvexpbar.dll 2009-08-20 18:45 446,464 a——- c:\windows\system32\NVUNINST.EXE 2009-08-20 18:45 934,912 a——- c:\windows\system32\drivers\AVerBDA716x.sys 2009-08-20 18:45 147,877 a——- c:\windows\system32\MV716x.ax 2009-08-20 18:45 3,072 a——- c:\windows\system32\716xCoInstaller.dll 2009-08-20 18:45 –d—– c:\windows\Driver Cache 2009-08-20 18:45 –d—– c:\program files\AVerMedia 2009-08-20 18:44 0 a—h— c:\windows\system32\drivers\Msft_Kernel_SynTP_01000.Wdf 2009-08-20 18:44 –d—– c:\program files\Synaptics 2009-08-20 18:44 –d—– c:\windows\system32\ENU 2009-08-20 18:44 1,034,776 a——- c:\windows\system32\imsmudlg.exe 2009-08-20 18:44 319,456 a——- c:\windows\system32\difxapi.dll 2009-08-20 18:44 –d—– c:\windows\system32\Lang 2009-08-20 18:44 312,344 a——- c:\windows\system32\drivers\iaStor.sys 2009-08-20 18:43 –d—– c:\windows\system32\HPMDP 2009-08-20 18:43 118,784 a——- c:\windows\system32\drivers\Rtlh86.sys 2009-08-20 18:43 –d—– c:\program files\Realtek 2009-08-20 18:43 54,824 ——– c:\windows\system32\agrsmdel.exe 2009-08-20 18:42 –d—– c:\windows\Options 2009-08-20 18:42 –d—– C:\SWSetup 2009-08-20 18:42 –d—– c:\users\o0virg~1\appdata\roaming\Hewlett Packard 2009-08-20 18:42 –d—– c:\program files\Validity Sensors, Inc 2009-08-20 18:42 –dsh— c:\windows\Installer 2009-08-20 18:41 251 a——- c:\windows\xUninstall.bat 2009-08-20 18:41 15,086 a——- c:\windows\system32\jmcr_xd.ico 2009-08-20 18:41 15,086 a——- c:\windows\system32\jmcr_ms.ico 2009-08-20 18:41 15,086 a——- c:\windows\system32\jmcr_mmc.ico 2009-08-20 18:41 –d—– c:\windows\JMCR_DIR 2009-08-20 18:40 53,248 a——- c:\windows\system32\CSVer.dll 2009-08-20 18:39 –d—– c:\program files\IDT 2009-08-20 07:58 –d—– c:\programdata\Adobe 2009-08-20 07:57 –d—– c:\program files\common files\Macrovision Shared 2009-08-20 07:06 –d—– c:\programdata\Yahoo! 2009-08-20 07:06 –d—– c:\program files\Yahoo! 2009-08-20 06:57 32,592 a——- c:\windows\system32\msonpmon.dll 2009-08-20 06:55 –d—– c:\windows\PCHEALTH 2009-08-20 06:50 –d—– c:\program files\Microsoft Visual Studio 8 2009-08-20 06:50 –d—– c:\programdata\Microsoft Help 2009-08-20 06:41 –d—– c:\users\o0virg~1\appdata\roaming\IDM 2009-08-20 06:41 –d—– c:\users\o0virg~1\appdata\roaming\DMCache 2009-08-20 06:38 –d—– c:\program files\common files\PX Storage Engine 2009-08-20 06:38 –d—– c:\windows\system32\IOSUBSYS 2009-08-20 06:26 –d—– c:\windows\Lhsp 2009-08-20 06:26 –d—– c:\programdata\InstallShield 2009-08-20 06:26 58,368 a——- c:\windows\system32\TCaptureX.dll 2009-08-20 06:26 385,100 a——- c:\windows\system32\Msvcrtd.dll 2009-08-20 06:26 98,304 a——- c:\windows\system32\TCapture.dll 2009-08-20 06:26 27,648 a——- c:\windows\system32\RL.dll 2009-08-20 06:26 7,168 a——- c:\windows\system32\TCCustom.dll 2009-08-20 06:15 –d—– c:\users\o0virg~1\appdata\roaming\MTD 2009-08-20 06:11 –d—– c:\program files\common files\MSSoap 2009-08-20 06:11 –d—– c:\program files\common files\L&H 2009-08-20 06:04 –d—– c:\users\o0virg~1\appdata\roaming\Foxit 2009-08-20 05:57 –d—– c:\program files\common files\EZB Systems 2009-08-20 05:47 1,638,912 a——- c:\windows\system32\mshtml.tlb 2009-08-20 05:37 a-d—– c:\programdata\TEMP 2009-08-20 05:37 –d—– c:\users\o0virg~1\appdata\roaming\URSoft 2009-08-16 10:55 –d—– c:\windows\system32\vi-VN 2009-08-16 10:55 –d—– c:\windows\system32\eu-ES 2009-08-16 10:55 –d—– c:\windows\system32\ca-ES 2009-08-16 10:52 –d—– c:\windows\system32\SPReview 2009-08-16 10:47 928,768 a——- c:\windows\system32\scavenge.dll 2009-08-16 10:46 57,856 a——- c:\windows\system32\compcln.exe 2009-08-16 10:43 3,408,896 a——- c:\windows\system32\SLsvc.exe 2009-08-16 10:41 –d—– c:\windows\system32\EventProviders 2009-08-16 10:25 –d—– c:\windows\Panther 2009-08-16 10:06 193,024 a——- c:\windows\system32\recdisc.exe 2009-08-16 10:06 6,656 a——- c:\windows\system32\sdspres.dll 2009-08-16 10:06 28,160 a——- c:\windows\system32\sxproxy.dll 2009-08-16 10:04 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll 2009-08-16 10:03 6,656 a——- c:\windows\system32\kbd106n.dll 2009-08-16 10:02 196,608 a——- c:\windows\SPInstall.etl 2009-08-16 09:41 –d—– c:\users\o0 Virgo 0o ==================== Find3M ==================== 2009-08-21 03:14 143,360 a——- c:\windows\inf\infstrng.dat 2009-08-21 03:14 86,016 a——- c:\windows\inf\infstor.dat 2009-08-21 03:14 51,200 a——- c:\windows\inf\infpub.dat 2009-08-16 10:54 665,600 a——- c:\windows\inf\drvindex.dat 2009-08-16 10:31 174 a–sh— c:\program files\desktop.ini 2009-08-16 10:18 101,888 a——- c:\windows\system32\ifxcardm.dll 2009-08-16 10:18 82,432 a——- c:\windows\system32\axaltocm.dll 2009-07-22 04:52 915,456 a——- c:\windows\system32\wininet.dll 2009-07-22 04:47 109,056 a——- c:\windows\system32\iesysprep.dll 2009-07-22 04:47 71,680 a——- c:\windows\system32\iesetup.dll 2009-07-22 03:13 133,632 a——- c:\windows\system32\ieUnatt.exe 2009-06-02 23:11 85,504 a——- c:\windows\system32\ff_vfw.dll 2009-05-30 04:37 205,824 a——- c:\windows\system32\xvidvfw.dll 2009-05-30 04:31 881,664 a——- c:\windows\system32\xvidcore.dll 2006-11-02 19:40 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 19:40 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 19:40 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 19:40 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 16:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 16:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 16:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 16:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 10:22:44.45 =============== Attack .txt ——————————————————————————————————————————————————————————– UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-07-30.01) Microsoft® Windows Vista™ Ultimate Boot Device: \Device\HarddiskVolume1 Install Date: 8/16/2009 9:35:35 AM System Uptime: 8/25/2009 6:30:21 AM (4 hours ago) Motherboard: Quanta | | 3603 Processor: Intel® Core™2 Duo CPU T9400 @ 2.53GHz | CPU | 2534/1066mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 80 GiB total, 60.096 GiB free. D: is FIXED (NTFS) - 80 GiB total, 34.204 GiB free. E: is FIXED (NTFS) - 128 GiB total, 33.129 GiB free. F: is FIXED (NTFS) - 10 GiB total, 1.662 GiB free. G: is CDROM () H: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== No restore point in system. ==== Installed Programs ====================== Adobe AIR Adobe Anchor Service CS4 Adobe Bridge CS4 Adobe CMaps CS4 Adobe Color - Photoshop Specific CS4 Adobe Color EU Extra Settings CS4 Adobe Color JA Extra Settings CS4 Adobe Color NA Recommended Settings CS4 Adobe Color Video Profiles CS CS4 Adobe CSI CS4 Adobe Default Language CS4 Adobe Device Central CS4 Adobe Drive CS4 Adobe ExtendScript Toolkit CS4 Adobe Extension Manager CS4 Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Fonts All Adobe Linguistics CS4 Adobe Media Player Adobe Output Module Adobe PDF Library Files CS4 Adobe Photoshop CS4 Adobe Photoshop CS4 Support Adobe Search for Help Adobe Service Manager Extension Adobe Setup Adobe Shockwave Player Adobe Type Support CS4 Adobe Update Manager CS4 Adobe WinSoft Linguistics Plugin Adobe XMP Panels CS4 AdobeColorCommonSetCMYK AdobeColorCommonSetRGB Agere Systems HDA Modem AVerMedia MCE Encoder x86 [removed] CCleaner (remove only) Connect CyberLink YouCam DigitalPersona Personal 3.0.1 ESET Smart Security Foxit Reader Hewlett-Packard Active Check for Health Check Hewlett-Packard Asset Agent for Health Check HP Active Support Library HP Help and Support HP Integrated Module with Bluetooth wireless technology 6.0.1.6200 HP MiniCard Hybrid TV [removed] HP MULTIPLE MODEM INSTALLER for VISTA HP Quick Launch Buttons 6.40 H2 HP QuickPlay 3.7 HP QuickTouch 1.00 D2 HP Update HP User Guides 0102 HP Wireless Assistant HPNetworkAssistant IDT Audio Intel® Matrix Storage Manager Internet Download Manager Java™ 6 Update 5 Javidic 2008 Final JMicron JMB38X Flash Media Controller K-Lite Mega Codec Pack 5.0.5 kuler L&H TTS3000 British English L&H TTS3000 Japanese Lac Viet mtd9 EVA LacViet mtdCVH 2005 Malwarebytes' Anti-Malware Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Visual C++ 2005 Redistributable Mozilla Firefox (3.5.2) muvee autoProducer 6.1 NOD32 v3.0.642 FiX1.2 by TemDono (31 days remaining forever up NVIDIA Drivers PDF Settings CS4 Photoshop Camera Raw Picasa 3 ProDic 2007 ProtectSmart Hard Drive Protection QuickPlay SlingPlayer 0.4.6 Razer Copperhead Realtek 8169 8168 8101E 8102E Ethernet Driver Spyware Doctor 6.1 Suite Shared Configuration CS4 Synaptics Pointing Device Driver UltraISO Premium V9.33 Unlocker 1.8.7 Validity Sensors software WinRAR archiver Yahoo! Messenger Your Uninstaller! 2008 Version 6.2 ==== Event Viewer Messages From Past Week ======== 8/25/2009 6:32:43 AM, Error: Service Control Manager [7022] - The QuickPlay Task Scheduler (QTS) service hung on starting. 8/25/2009 6:32:43 AM, Error: Service Control Manager [7022] - The QuickPlay Background Capture Service (QBCS) service hung on starting. 8/25/2009 6:32:21 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Eset Nod32 Boot service to connect. 8/25/2009 6:32:21 AM, Error: Service Control Manager [7000] - The Eset Nod32 Boot service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 8/25/2009 10:11:20 AM, Error: Service Control Manager [7034] - The PC Tools Security Service service terminated unexpectedly. It has done this 1 time(s). 8/24/2009 11:44:04 PM, Error: netbt [4321] - The name "WORKGROUP :1d" could not be registered on the interface with IP address 192.168.1.192. The computer with the IP address 192.168.1.100 did not allow the name to be claimed by this computer. 8/24/2009 11:44:04 PM, Error: BROWSER [8009] - The browser was unable to promote itself to master browser. The computer that currently believes it is the master browser is PC375266281045. 8/21/2009 3:14:06 AM, Error: Service Control Manager [7030] - The ESET Service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. 8/21/2009 2:23:13 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service sdrsvc with arguments "" in order to run the server: {47135EEA-06B6-4452-8787-4A187C64A47E} 8/21/2009 1:06:03 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: spldr Wanarpv6 8/21/2009 1:06:03 AM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 8/21/2009 1:05:19 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030} 8/21/2009 1:05:14 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF} 8/21/2009 1:05:12 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 8/21/2009 1:05:04 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} 8/20/2009 6:59:15 PM, Error: Service Control Manager [7030] - The QuickPlay Task Scheduler (QTS) service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. 8/20/2009 6:59:15 PM, Error: Service Control Manager [7030] - The QuickPlay Background Capture Service (QBCS) service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. 8/20/2009 6:57:17 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect. 8/20/2009 6:57:17 AM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 8/20/2009 6:57:17 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} 8/20/2009 6:45:45 PM, Error: Service Control Manager [7001] - The NVIDIA Display Driver Service service depends on the nvlddmkm service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 8/20/2009 6:05:14 AM, Error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. ==== End Of File =========================== rootreal.txt——————————————————————————————————————————————————————————– ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/08/25 10:34 Program Version: Version 1.3.5.0 Windows Version: Windows Vista SP2 ================================================== Drivers ——————- Name: dump_dumpfve.sys Image Path: C:\Windows\System32\Drivers\dump_dumpfve.sys Address: 0x91B55000 Size: 69632 File Visible: No Signed: - Status: - Name: dump_iaStor.sys Image Path: C:\Windows\System32\Drivers\dump_iaStor.sys Address: 0x91A87000 Size: 843776 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\Windows\system32\drivers\rootrepeal.sys Address: 0x9EE00000 Size: 49152 File Visible: No Signed: - Status: - Hidden/Locked Files ——————- Path: C:\hiberfil.sys Status: Locked to the Windows API! Path: C:\Windows\System32\kbiwkmkkdojbmc.dll Status: Invisible to the Windows API! Path: C:\Windows\System32\kbiwkmpafwdqnp.dat Status: Invisible to the Windows API! Path: C:\Windows\System32\kbiwkmswpipcyr.dll Status: Invisible to the Windows API! Path: C:\Windows\System32\kbiwkmustvxpuv.dat Status: Invisible to the Windows API! Path: C:\Users\o0 Virgo 0o\Documents\My Music Status: Locked to the Windows API! Path: C:\Users\o0 Virgo 0o\Documents\My Pictures Status: Locked to the Windows API! Path: C:\Users\o0 Virgo 0o\Documents\My Videos Status: Locked to the Windows API! Path: C:\Windows\System32\drivers\kbiwkmxsxvqsnu.sys Status: Invisible to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.42_none_0e9c2a8d74fd3c e6.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed .cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.debugcrt_1fc8b3b9a1e18e3b_9.0.30729.1_none_bb1f6aa1308c3 5eb.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_8550c6b 5d18a9128.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d 131.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_8e053 e8c6967ba9d.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_none_58b19c 2866332652.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_none_54c11d f268b7c6d9.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c .cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.debugcrt_1fc8b3b9a1e18e3b_9.0.30729.1_none_61 305e07e4f1bc01.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8d d7dea5d5a7a18a.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_9193a 620671dde41.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada.c at Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf.c at Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_5c4003 bc63e949f6.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.762_none_ab ac38a907ee8801.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.762_none_7b33aa7d21850 4d2.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_7dd1e0e bd6590e0b.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_none_d6c3e7af9bae13a2. cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.42_none_588 43c41d2730d3f.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8a14c 0566bec5b24.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_db5f52fb98cb24ad. cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_10b2f55f9bffb8f8 .cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_none_dc990e4797f81af1. cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-a..atibility-assistant_31bf3856ad364e35_6.0.6000.16386_none_318fc418263bf156\$$DeleteMe.pcadm.dll.01ca1e214478771a.00dc Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-a..atibility-assistant_31bf3856ad364e35_6.0.6000.16386_none_318fc418263bf156\$$DeleteMe.pcasvc.dll.01ca1e2142eaf17a.0094 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-a..dcredentialprovider_31bf3856ad364e35_6.0.6000.16386_none_3fd3e2bdc5a2408e\$$DeleteMe.SmartcardCredentialProvider.dll.01ca1e2143325aba.00a0 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-a..dcredentialprovider_31bf3856ad364e35_6.0.6001.18000_none_420aa4b9c28d5162\$$DeleteMe.SmartcardCredentialProvider.dll.01ca1e2558f626bb.005d Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.0.6000.16386_none_d2da41c24fcec5ef\$$DeleteMe.apphelp.dll.01ca1e21441ba17a.00c9 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.0.6001.18000_none_d51103be4cb9d6c3\$$DeleteMe.apphelp.dll.01ca1e255947157b.0081 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-a..es-interface-router_31bf3856ad364e35_6.0.6000.16386_none_55bf44ac819e1c73\$$DeleteMe.activeds.dll.01ca1e213e8e8c9a.0047 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-a..o-mmecore-wdm-audio_31bf3856ad364e35_6.0.6000.16386_none_48178a2ae8c70f33\$$DeleteMe.wdmaud.drv.01ca1e2140fbd37a.0073 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-a..on-authui.resources_31bf3856ad364e35_6.0.6000.16386_en-us_8945d572a01e6a1a\$$DeleteMe.authui.dll.mui.01ca1e214976b97a.00fc Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-a..terface-ldapc-layer_31bf3856ad364e35_6.0.6000.16386_none_5cfbb23d699248a8\$$DeleteMe.adsldpc.dll.01ca1e213ef4e7ba.0056 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-a..terface-ldapc-layer_31bf3856ad364e35_6.0.6001.18000_none_5f327439667d597c\$$DeleteMe.adsldpc.dll.01ca1e25585dcebb.002e Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-advapi32.resources_31bf3856ad364e35_6.0.6000.16386_en-us_1652b637b3e9dec3\$$DeleteMe.advapi32.dll.mui.01ca1e2149ca099a.0106 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-advapi32_31bf3856ad364e35_6.0.6000.16386_none_e1118fae8996a7dc\$$DeleteMe.advapi32.dll.01ca1e213d67621a.0032 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-advapi32_31bf3856ad364e35_6.0.6001.18000_none_e34851aa8681b8b0\$$DeleteMe.advapi32.dll.01ca1e2558035a7b.0018 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6000.16386_none_7469022ae7b4af06\$$DeleteMe.audiodg.exe.01ca1e213daecb5a.0033 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6000.16386_none_7469022ae7b4af06\$$DeleteMe.AudioEng.dll.01ca1e21422a221a.0080 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6000.16386_none_7469022ae7b4af06\$$DeleteMe.AUDIOKSE.dll.01ca1e2140f710ba.0072 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6000.16386_none_7469022ae7b4af06\$$DeleteMe.AudioSes.dll.01ca1e2143182b9a.009b Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6000.16386_none_7469022ae7b4af06\$$DeleteMe.audiosrv.dll.01ca1e2143f58b7a.00c1 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6001.18000_none_769fc426e49fbfda\$$DeleteMe.audiodg.exe.01ca1e255805bbdb.0019 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6001.18000_none_769fc426e49fbfda\$$DeleteMe.AudioSes.dll.01ca1e2558ef029b.005b Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6001.18000_none_769fc426e49fbfda\$$DeleteMe.audiosrv.dll.01ca1e25593b2e9b.007a Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-audio-mmecore-acm_31bf3856ad364e35_6.0.6000.16386_none_deaec722e41e5e07\$$DeleteMe.msacm32.dll.01ca1e213c5cc81a.0018 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-audio-mmecore-base_31bf3856ad364e35_6.0.6000.16386_none_b3a8fa3e54c50ab3\$$DeleteMe.winmm.dll.01ca1e2143b2e4fa.00b3 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-audio-mmecore-base_31bf3856ad364e35_6.0.6001.18000_none_b5dfbc3a51b01b87\$$DeleteMe.winmm.dll.01ca1e255920ff7b.006d Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-authentication-authui_31bf3856ad364e35_6.0.6000.16386_none_09bcbb1af87cd123\$$DeleteMe.authui.dll.01ca1e2142d5851a.008d Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-authentication-authui_31bf3856ad364e35_6.0.6001.18000_none_0bf37d16f567e1f7\$$DeleteMe.authui.dll.01ca1e2558d734db.0053 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-authentication-logonui_31bf3856ad364e35_6.0.6000.16386_none_635c5092764d99de\$$DeleteMe.LogonUI.exe.01ca1e2142b431da.0088 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-atl_31bf3856ad364e35_6.0.6000.16386_none_a8e97dca5cc75c13\$$DeleteMe.atl.dll.01ca1e21433be03a.00a2 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-audio-mmecore-other_31bf3856ad364e35_6.0.6000.16386_none_8ac7060813a4d0d2\$$DeleteMe.midimap.dll.01ca1e21431368da.0098 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-audio-mmecore-other_31bf3856ad364e35_6.0.6000.16386_none_8ac7060813a4d0d2\$$DeleteMe.msacm32.drv.01ca1e2145bc321a.00e5 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_sv-se_026709e97133efc3\BOOTMG~1.MUI Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_tr-tr_ab7454305feff1b4\BOOTMG~1.MUI Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_zh-cn_7cd1722e1027c3d3\BOOTMG~1.MUI Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_zh-hk_7b7c6abc11033663\BOOTMG~1.MUI Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_zh-tw_80cdaf840d98a043\BOOTMG~1.MUI Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_sv-se_9bfb2a309351ac4c\BOOTMG~1.MUI Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_tr-tr_45087477820dae3d\BOOTMG~1.MUI Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_zh-cn_166592753245805c\BOOTMG~1.MUI Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_zh-hk_15108b033320f2ec\BOOTMG~1.MUI Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_zh-tw_1a61cfcb2fb65ccc\BOOTMG~1.MUI Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-basesrv_31bf3856ad364e35_6.0.6000.16386_none_0a9428d9e6cfbcfc\$$DeleteMe.basesrv.dll.01ca1e21391e083a.000e Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-bits-client_31bf3856ad364e35_6.0.6000.16386_none_215a02f0fc86fab8\$$DeleteMe.qmgr.dll.01ca1e2142066d7a.007c Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-bits-client_31bf3856ad364e35_6.0.6001.18000_none_2390c4ecf9720b8c\$$DeleteMe.qmgr.dll.01ca1e2558b5e19b.004a Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-bits-igdsearcher_31bf3856ad364e35_6.0.6000.16386_none_af357b0d92153e84\$$DeleteMe.bitsigd.dll.01ca1e21410c7d1a.0075 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-bits-igdsearcher_31bf3856ad364e35_6.0.6001.18000_none_b16c3d098f004f58\$$DeleteMe.bitsigd.dll.01ca1e25589e13db.0043 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.0.6000.16386_none_0ab6dd2154d28f55\$$DeleteMe.es.dll.01ca1e2143e9a49a.00c0 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.0.6001.18000_none_0ced9f1d51bda029\$$DeleteMe.es.dll.01ca1e255938cd3b.0079 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-c..complus-runtime-qfe_31bf3856ad364e35_6.0.6000.16386_none_692c6c857ba3c205\$$DeleteMe.clbcatq.dll.01ca1e21445723da.00d7 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-c..ent-indexing-common_31bf3856ad364e35_6.0.6001.18000_none_06b40dcad71051f6\$$DeleteMe.Query.dll.01ca1e2558b11edb.0046 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-c..ent-indexing-common_31bf3856ad364e35_6.0.6000.16386_none_047d4bceda254122\$$DeleteMe.Query.dll.01ca1e2141f5c3da.0078 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-c..rformance-xperfcore_31bf3856ad364e35_6.0.6000.16386_none_d4dab19871ad5771\$$DeleteMe.diagperf.dll.01ca1e2144b65ada.00df Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-c..rformance-xperfcore_31bf3856ad364e35_6.0.6001.18000_none_d71173946e986845\$$DeleteMe.diagperf.dll.01ca1e2559b2335b.0090 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-cabinet_31bf3856ad364e35_6.0.6000.16386_none_35088f20e500a372\$$DeleteMe.cabinet.dll.01ca1e2143c8515a.00b6 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-cbsapi_31bf3856ad364e35_6.0.6000.16386_none_4c2b1119f37be620\$$DeleteMe.CbsApi.dll.01ca1e1f68a11364.0001 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-cmi_31bf3856ad364e35_6.0.6000.16386_none_a797884c5d9fcdc5\$$DeleteMe.cmiv2.dll.01ca1e2147879b7a.00f5 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-cmi_31bf3856ad364e35_6.0.6001.18000_none_a9ce4a485a8ade99\$$DeleteMe.cmiv2.dll.01ca1e255aa29e3b.00a1 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-coreusermodepnp_31bf3856ad364e35_6.0.6001.18000_none_7701ab362cebf905\$$DeleteMe.umpnpmgr.dll.01ca1e2559555dbb.0089 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-coreos_31bf3856ad364e35_6.0.6000.16386_none_231b844b41663663\$$DeleteMe.imagehlp.dll.01ca1e2144310dda.00ce Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-coreusermodepnp_31bf3856ad364e35_6.0.6000.16386_none_74cae93a3000e831\$$DeleteMe.umpnpmgr.dll.01ca1e1fc0fb8848.0000 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-coreusermodepnp_31bf3856ad364e35_6.0.6000.16609_none_75246f2a2fbd4c23\$$DeleteMe.cfgmgr32.dll.01ca1e214208ceda.007d Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-coreusermodepnp_31bf3856ad364e35_6.0.6000.16609_none_75246f2a2fbd4c23\$$DeleteMe.umpnpmgr.dll.01ca1e21444d9e5a.00d3 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-credui_31bf3856ad364e35_6.0.6000.16386_none_d9008ac592026334\$$DeleteMe.credui.dll.01ca1e213c44fa5a.0014 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-credui_31bf3856ad364e35_6.0.6001.18000_none_db374cc18eed7408\$$DeleteMe.credui.dll.01ca1e2557c576bb.0009 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-crypt32-dll_31bf3856ad364e35_6.0.6000.16386_none_5938ffdfe0e8b606\$$DeleteMe.crypt32.dll.01ca1e2143560f5a.00a7 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-crypt32-dll_31bf3856ad364e35_6.0.6001.18000_none_5b6fc1dbddd3c6da\$$DeleteMe.crypt32.dll.01ca1e25590df47b.0062 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-cryptdll-dll_31bf3856ad364e35_6.0.6000.16386_none_0367c3eab0da6051\$$DeleteMe.cryptdll.dll.01ca1e2142e3cd5a.0092 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6000.16386_none_73c8d7689de43d15\$$DeleteMe.cryptsvc.dll.01ca1e214057949a.0061 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6001.18000_none_75ff99649acf4de9\$$DeleteMe.cryptsvc.dll.01ca1e255877fddb.0037 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-csrsrv_31bf3856ad364e35_6.0.6000.16386_none_c7507509a87290f5\$$DeleteMe.csrsrv.dll.01ca1e213916e41a.000a Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-csrss_31bf3856ad364e35_6.0.6000.16386_none_56ad21dbe72a9d78\$$DeleteMe.csrss.exe.01ca1e213912215a.0008 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_sv-se_81fc82c1607b7353\BOOTMG~1.MUI Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_zh-cn_fc66eb05ff6f4763\BOOTMG~1.MUI Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_zh-hk_fb11e394004ab9f3\BOOTMG~1.MUI Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_zh-tw_0063285bfce023d3\BOOTMG~1.MUI Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-d..oryservices-ntdsapi_31bf3856ad364e35_6.0.6000.16386_none_cca68469f44b4003\$$DeleteMe.ntdsapi.dll.01ca1e213e87687a.0046 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-d..pwindowmanager-core_31bf3856ad364e35_6.0.6000.16386_none_8b6cd218c046ea63\$$DeleteMe.uxsms.dll.01ca1e2144310dda.00cf Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-d..pwindowmanager-core_31bf3856ad364e35_6.0.6001.18000_none_8da39414bd31fb37\$$DeleteMe.uxsms.dll.01ca1e25594e399b.0084 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-d..pwindowmanager-core_31bf3856ad364e35_6.0.6002.18005_none_8f8f0d20ba53c683\MICROS~1.XRM Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_tr-tr_2b09cd084f377544\BOOTMG~1.MUI Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-deltacompressionengine_31bf3856ad364e35_6.0.6000.16386_none_3df5a61c88d408ee\$$DeleteMe.mspatcha.dll.01ca1e213cc3233a.0028 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-deltapackageexpander_31bf3856ad364e35_6.0.6000.16609_none_68015a2337d92e69\$$DeleteMe.dpx.dll.01ca1e2142e8901a.0093 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.0.6000.16386_none_afb79761a4097d90\$$DeleteMe.samlib.dll.01ca1e2141e51a3a.0077 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.0.6000.16386_none_afb79761a4097d90\$$DeleteMe.samsrv.dll.01ca1e213d414c1a.002e Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.0.6001.18000_none_b1ee595da0f48e64\$$DeleteMe.samlib.dll.01ca1e2558aebd7b.0045 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.0.6001.18000_none_b1ee595da0f48e64\$$DeleteMe.samsrv.dll.01ca1e2557fc365b.0016 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client-winrnr_31bf3856ad364e35_6.0.6000.16386_none_571790f3532b2696\$$DeleteMe.winrnr.dll.01ca1e2559c07b9b.0093 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.0.6000.16386_none_dfabbae1856e5297\$$DeleteMe.dnsapi.dll.01ca1e213d16735a.002b Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.0.6000.16386_none_dfabbae1856e5297\$$DeleteMe.dnsrslvr.dll.01ca1e213eb4a29a.004e Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.0.6001.18000_none_e1e27cdd8259636b\$$DeleteMe.dnsapi.dll.01ca1e2557f2b0db.0015 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.0.6001.18000_none_e1e27cdd8259636b\$$DeleteMe.dnsrslvr.dll.01ca1e25584600fb.0029 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-duser_31bf3856ad364e35_6.0.6000.16386_none_583dec4cff8f7125\$$DeleteMe.duser.dll.01ca1e214460a95a.00d9 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-e..emorydevicesservice_31bf3856ad364e35_6.0.6000.16386_none_9c552a52f9cf5068\$$DeleteMe.emdmgmt.dll.01ca1e21435f94da.00a8 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-e..emorydevicesservice_31bf3856ad364e35_6.0.6001.18000_none_9e8bec4ef6ba613c\$$DeleteMe.emdmgmt.dll.01ca1e255912b73b.0064 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-e..estorageengine-isam_31bf3856ad364e35_6.0.6000.16386_none_efad84e52f20ae35\$$DeleteMe.esent.dll.01ca1e2142df0a9a.0090 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-e..estorageengine-isam_31bf3856ad364e35_6.0.6001.18000_none_f1e446e12c0bbf09\$$DeleteMe.esent.dll.01ca1e2558e0ba5b.0056 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-eventlog-api_31bf3856ad364e35_6.0.6000.16386_none_a9fa4020685f2193\$$DeleteMe.wevtapi.dll.01ca1e213c853f7a.001e Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-eventlog-api_31bf3856ad364e35_6.0.6001.18000_none_ac31021c654a3267\$$DeleteMe.wevtapi.dll.01ca1e2557d6205b.000e Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-eventlog_31bf3856ad364e35_6.0.6000.16386_none_da8d9a1e15ee1eb0\$$DeleteMe.wevtsvc.dll.01ca1e213d5ddc9a.0030 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-eventlog_31bf3856ad364e35_6.0.6001.18000_none_dcc45c1a12d92f84\$$DeleteMe.wevtsvc.dll.01ca1e255800f91b.0017 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-failovercluster-client_31bf3856ad364e35_6.0.6000.16386_none_a4186fca55bd3a26\$$DeleteMe.clusapi.dll.01ca1e2140d81eda.006c Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-failovercluster-client_31bf3856ad364e35_6.0.6000.16386_none_a4186fca55bd3a26\$$DeleteMe.resutils.dll.01ca1e214315ca3a.009a Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-fax-common.resources_31bf3856ad364e35_6.0.6000.16386_en-us_4777ffb339c4e9f8\$$DeleteMe.FXSRESM.dll.mui.01ca1e214974581a.00fb Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-fax-service_31bf3856ad364e35_6.0.6000.16386_none_aaecd7c1835e5b9d\$$DeleteMe.FXSMON.dll.01ca1e2140d5bd7a.006b Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-feclient_31bf3856ad364e35_6.0.6000.16386_none_bca34f2f5aa9c40c\$$DeleteMe.feclient.dll.01ca1e214452611a.00d6 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-filtermanager-core_31bf3856ad364e35_6.0.6000.16386_none_0ed2b0f62de100b1\$$DeleteMe.fltMgr.sys.01ca1e213938375a.0010 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-fax-common_31bf3856ad364e35_6.0.6000.16386_none_09cdeced53b576c7\$$DeleteMe.FXSRESM.dll.01ca1e213c7e1b5a.001c Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-feclient_31bf3856ad364e35_6.0.6001.18000_none_beda112b5794d4e0\$$DeleteMe.feclient.dll.01ca1e25595a207b.008b Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-gdi32_31bf3856ad364e35_6.0.6000.16386_none_5747e8004c667a97\$$DeleteMe.gdi32.dll.01ca1e21434eeb3a.00a6 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-gdi32_31bf3856ad364e35_6.0.6001.18000_none_597ea9fc49518b6b\$$DeleteMe.gdi32.dll.01ca1e2558ffac3b.0061 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.16386_none_a79c567c5d9b4c78\$$DeleteMe.lpk.dll.01ca1e21445723da.00d8 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-grouppolicy-base_31bf3856ad364e35_6.0.6001.18000_none_282361dee702a605\$$DeleteMe.gpapi.dll.01ca1e2558b3803b.0049 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-grouppolicy-base_31bf3856ad364e35_6.0.6001.18000_none_282361dee702a605\$$DeleteMe.gpsvc.dll.01ca1e25591e9e1b.006b Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-grouppolicy-base_31bf3856ad364e35_6.0.6000.16386_none_25ec9fe2ea179531\$$DeleteMe.gpapi.dll.01ca1e214201aaba.007b Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-grouppolicy-base_31bf3856ad364e35_6.0.6000.16386_none_25ec9fe2ea179531\$$DeleteMe.gpsvc.dll.01ca1e2143abc0da.00b1 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-http-api_31bf3856ad364e35_6.0.6000.16386_none_f3757b03a060c8ff\$$DeleteMe.httpapi.dll.01ca1e2144121bfa.00c7 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6001.18000_none_b4e317dbd6c9eb53\$$DeleteMe.urlmon.dll.01ca1e255919db5b.0069 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-i..nal-core-locale-nls_31bf3856ad364e35_6.0.6000.16386_none_68816eddac5ab0fd\$$DeleteMe.locale.nls.01ca1e2145ab887a.00e2 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-i..nal-core-locale-nls_31bf3856ad364e35_6.0.6001.18000_none_6ab830d9a945c1d1\$$DeleteMe.locale.nls.01ca1e2559bbb8db.0091 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-i..oexistencemigration_31bf3856ad364e35_6.0.6000.16386_none_0fac50d67f6f5ad2\$$DeleteMe.iphlpsvc.dll.01ca1e21390fbffa.0007 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-i..oexistencemigration_31bf3856ad364e35_6.0.6001.18000_none_11e312d27c5a6ba6\$$DeleteMe.iphlpsvc.dll.01ca1e2555a1fa7b.0004 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16386_none_ffb23181a4e80112\$$DeleteMe.wininet.dll.01ca1e2142c73cda.008a Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18000_none_01e8f37da1d311e6\$$DeleteMe.wininet.dll.01ca1e2558d4d37b.0051 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.18005_none_03d46c899ef4dd32\$$DeleteMe.wininet.dll.01ca211f259adf90.0000 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-icm-base_31bf3856ad364e35_6.0.6000.16386_none_209128588c782871\$$DeleteMe.mscms.dll.01ca1e2141fce7fa.007a Status: Locked to the WindowProcesses ——————- Path: System PID: 4 Status: Locked to the Windows API! Path: C:\Windows\System32\audiodg.exe PID: 1260 Status: Locked to the Windows API! Stealth Objects ——————- Object: Hidden Module [Name: kbiwkmkkdojbmc.dll] Process: svchost.exe (PID: 876) Address: 0x10000000 Size: 53248 Object: Hidden Module [Name: kbiwkmswpipcyr.dll] Process: Explorer.EXE (PID: 2824) Address: 0x10000000 Size: 32768 Object: Hidden Module [Name: kbiwkmswpipcyr.dll] Process: iexplore.exe (PID: 3140) Address: 0x10000000 Size: 32768 Object: Hidden Module [Name: kbiwkmswpipcyr.dll] Process: iexplore.exe (PID: 3672) Address: 0x10000000 Size: 32768 Hidden Services ——————- Service Name: kbiwkmmmowhqoe Image Path: C:\Windows\system32\drivers\kbiwkmxsxvqsnu.sys ==EOF==

Could you give me your Yahoo messenger contact to ask about this ? thank you.

We only answer threads in the forums


Please do the following:

Download Combofix from either of the links below. You must rename it before saving it.
Save it to your desktop.

**Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".


Link 1
Link 2



During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.


———————————————————–

  • Double click on Combo-Fix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\Combo-Fix.txt" for further review.
    **Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**


    ———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–


Anyway, thanks.

I am scanning with Combo-Fix (after renamed). How long does it takes ? My disk is 320GB, C drive is 80GB.

I just dont know why it 's still in C:\ drive, even if I reinstalled Vista OS ???
It 's in others drive like a type of Dashfer ???

Could we remove it by deleting some *.dll or * .sys ?

————————————————-
Object: Hidden Module [Name: kbiwkmkkdojbmc.dll]
Process: svchost.exe (PID: 876) Address: 0x10000000 Size: 53248

Object: Hidden Module [Name: kbiwkmswpipcyr.dll]
Process: Explorer.EXE (PID: 2824) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: kbiwkmswpipcyr.dll]
Process: iexplore.exe (PID: 3140) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: kbiwkmswpipcyr.dll]
Process: iexplore.exe (PID: 3672) Address: 0x10000000 Size: 32768

Hidden Services
——————-
Service Name: kbiwkmmmowhqoe
Image Path: C:\Windows\system32\drivers\kbiwkmxsxvqsnu.sys
I double click in Combo - Fix . And, after it appear a window : combofix preparing to run… and it disappear, nothing happens. :-( No report in C: ? My HDD is 320, C drive is 80GB. So, how long does it take ?
It appears the infection is preventing it from working properly

please do the following:


Please save this file to your desktop.
Now click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" runbox, and click OK.
When it's finished, there will be a log called Win32kDiag.txt on your desktop.
Please open it with notepad and post the contents here.

"%userprofile%\desktop\win32kdiag.exe" -f -r


NEXT

delete the copy of combofix that you have on your desktop, download a fresh copy from one of the previous links provided.

Rename it to ComboFix.com

Try running it in safe mode.

Make sure all your security programs are disabled.
hic hic :-( :smack:

I did as you said. Use combo fix in safe mode with other name: Combofix.com

And, nothing happens again.

:-(


Thist is the win32kdiag content:

————————————————————————————————————————————-

Log file is located at: C:\Users\o0 Virgo 0o\Desktop\Win32kDiag.txt

Removing all found mount points.

Attempting to reset file permissions.

WARNING: Could not get backup privileges!

Searching 'C:\Windows'…



Cannot access: C:\Windows\bthservsdp.dat

Attempting to restore permissions of : C:\Windows\bthservsdp.dat

[1] 2009-08-25 19:28:41 12 C:\Windows\bthservsdp.dat ()



Cannot access: C:\Windows\CSC\v2.0.6\pq

Attempting to restore permissions of : C:\Windows\CSC\v2.0.6\pq
Hi,

Please do the following:

1. Please download The Avenger2 by Swandog46 to your Desktop.
  • Right click on the Avenger.zip folder and select "Extract All…"
  • Follow the prompts and extract the avenger folder to your desktop
2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):
Begin copying here:

Drivers to delete:
kbiwkmmmowhqoe

Files to delete:
C:\Windows\System32\kbiwkmkkdojbmc.dll
C:\Windows\System32\kbiwkmpafwdqnp.dat
C:\Windows\System32\kbiwkmswpipcyr.dll
C:\Windows\System32\kbiwkmustvxpuv.dat
C:\Windows\System32\drivers\kbiwkmxsxvqsnu.sys

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Now, open the Avenger folder and start The Avenger program by clicking on its icon.
  • Right click on the window under Input script here:, and select Paste.
  • You can also Paste the text copied to the clipboard into this window by pressing (Ctrl+V), or click on the third button under the menu to paste it from the clipboard.
  • Click on Execute
  • Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete" or "Drivers to Disable", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply


NEXT


Please try running ComboFix once more

try renaming it to winlogon.exe
Oh, you are careful person, guided me in evey detail .


This is the content of Avenger .txt. It seems some *.dll can't be deleted :-(

================================================================================
=========
//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows NT 6.0 (build 6002, Service Pack 2)
Wed Aug 26 03:45:27 2009

03:45:27: Error: Could not register cleanup.
Aborting execution! (error 0: the operation completed successfully.)


//////////////////////////////////////////


Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows Vista

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

Driver "kbiwkmmmowhqoe" deleted successfully.

Error: could not delete file "C:\Windows\System32\kbiwkmkkdojbmc.dll"
Deletion of file "C:\Windows\System32\kbiwkmkkdojbmc.dll" failed!
Status: 0xc0000156


Error: could not delete file "C:\Windows\System32\kbiwkmpafwdqnp.dat"
Deletion of file "C:\Windows\System32\kbiwkmpafwdqnp.dat" failed!
Status: 0xc0000156


Error: could not delete file "C:\Windows\System32\kbiwkmswpipcyr.dll"
Deletion of file "C:\Windows\System32\kbiwkmswpipcyr.dll" failed!
Status: 0xc0000156


Error: could not delete file "C:\Windows\System32\kbiwkmustvxpuv.dat"
Deletion of file "C:\Windows\System32\kbiwkmustvxpuv.dat" failed!
Status: 0xc0000156


Error: could not delete file "C:\Windows\System32\drivers\kbiwkmxsxvqsnu.sys"
Deletion of file "C:\Windows\System32\drivers\kbiwkmxsxvqsnu.sys" failed!
Status: 0xc0000156


Completed script processing.

*******************

Finished! Terminate.
And, I can't use ComboFix, like before. After a Window appear with " Commbofix preparing to scan… " it disappears. Then, Winlogon.exe automatically rename ComboFix.exe :-( Spyware doctor detect a trojan : trojan.zapchast!sd6 …. I'm worried.
Hi,

Please do the following:


  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.


NEXT

  • Download RootRepeal from the following location and save it to your desktop.
  • Extract RootRepeal.exe from the archive.
  • Open [external image: Posted Image] on your desktop.
  • Click the [external image: Posted Image] tab.
  • Click the [external image: Posted Image] button.
  • Check all seven boxes: [external image: Posted Image]
  • Push Ok
  • Check the box for your main system drive (Usually C:), and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.

NEXT

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries




NOTE: Try running GMER in safe mode - rename it to REMG.com if it wont run - and try again.
Extras.txt content

================================================================================
==========
OTL Extras logfile created on: 8/26/2009 8:28:32 AM - Run 1
OTL by OldTimer - Version 3.0.10.7 Folder = C:\Users\o0 Virgo 0o\Desktop
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18813)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.76 Gb Available Physical Memory | 87.95% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 80.02 Gb Total Space | 60.40 Gb Free Space | 75.48% Space Free | Partition Type: NTFS
Drive D: | 80.01 Gb Total Space | 34.19 Gb Free Space | 42.73% Space Free | Partition Type: NTFS
Drive E: | 128.37 Gb Total Space | 34.76 Gb Free Space | 27.08% Space Free | Partition Type: NTFS
Drive F: | 9.58 Gb Total Space | 1.66 Gb Free Space | 17.34% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KEI-LAP
Current User Name: o0 Virgo 0o
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{103AEEA9-9B8F-4169-929B-7C4819AA08CD}" = lport=5353 | protocol=6 | dir=in | name=adobe csi cs4 |
"{6858130A-3A16-4DC4-A279-C0D2D979DF47}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04D0E3CB-B3B4-4E31-A2E8-062453044F53}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe |
"{3128B626-9E7D-4C11-A7C0-F5D2F4A98ED8}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{4748A060-01ED-42A0-8ED0-85841D311823}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{56455DD1-3D14-4774-8DE9-AD907E8C46F8}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{64360198-D8D4-4438-8D6F-6BBACFE42F7B}" = protocol=17 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{85F15BBD-3966-4A53-BC85-4E3B6946F6DA}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{A81D3BAF-2DAE-4452-8DDC-4E8AABB9FC60}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{B0FED4C7-9793-41C3-81C5-2D7D9B18BF77}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{BC59EA95-FB1E-427E-9C97-B23EF8008F3D}" = protocol=6 | dir=in | app=c:\program files\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{F37CE7F3-0A15-4100-A8B9-43309CDEF30B}" = dir=in | app=c:\program files\hp\quickplay\qp.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{03D1988F-469F-4843-8E6E-E5FE9D17889D}" = HP Integrated Module with Bluetooth wireless technology 6.0.1.6200
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{09BA3667-5D11-4488-8896-15A8F793081E}" = Lac Viet mtd9 EVA
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check for Health Check
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron JMB38X Flash Media Controller
"{28A946E1-E83B-4662-BC7C-23451851489E}" = Razer Copperhead
"{28C3E5E6-5ACA-408D-9A46-089C5334EC97}" = HP Help and Support
"{30DAA715-5032-40F9-A0AE-95C9AEBB3E3F}" = HP QuickTouch 1.00 D2
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 H2
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{35F83303-C0C0-46B7-B8A8-ADA7C2AC5645}" = muvee autoProducer 6.1
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{45A136EC-88BF-4B95-99F5-C45D3930E1CC}" = HP MULTIPLE MODEM INSTALLER for VISTA
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.7
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4A536737-E71D-452F-984F-F8C0B0298226}" = LacViet mtdCVH 2005
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{567E8236-C414-4888-8211-3D61608D57AE}" = Validity Sensors software
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{9E2CCD5E-1990-4EF2-9B61-32F0BBACC29B}" = HP Active Support Library
"{A5CE7175-080D-49AC-B5A3-E7E3502428F5}" = HP Wireless Assistant
"{AAD72731-807A-4B79-AE05-9190B7002B7B}" = ProtectSmart Hard Drive Protection
"{AE72E414-0935-4AC8-B7D6-12E3039BEC13}" = DigitalPersona Personal 3.0.1
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B33D4FD7-41C0-482A-BBC7-57B606EC5F15}" = ProDic 2007
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E4848436-0345-47E2-B648-8B522FCDA623}" = Adobe Photoshop CS4
"{EBBD841E-945D-4C63-988D-8471BECD7950}" = Javidic 2008 Final
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F3E2505F-AA57-476B-9F67-F8C5E3938080}" = ESET Smart Security
"{F48098CD-2D66-4861-85EC-DC1D4D09D5F9}" = HP User Guides 0102
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_faf656ef605427ee2f42989c3ad31b8" = Adobe Photoshop CS4
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"AVerMedia MCE Encoder x86" = AVerMedia MCE Encoder x86 [removed]
"CCleaner" = CCleaner (remove only)
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Eset NOD32 v3.0.642 FiX1.2 by TemDono_is1" = NOD32 v3.0.642 FiX1.2 by TemDono (31 days remaining forever up
"Foxit Reader" = Foxit Reader
"HP MiniCard Hybrid TV" = HP MiniCard Hybrid TV [removed]
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{EBBD841E-945D-4C63-988D-8471BECD7950}" = Javidic 2008 Final
"Internet Download Manager" = Internet Download Manager
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 5.0.5
"LHTTSENG" = L&H TTS3000 British English
"LHTTSJPJ" = L&H TTS3000 Japanese
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.5.2)" = Mozilla Firefox (3.5.2)
"NVIDIA Drivers" = NVIDIA Drivers
"Picasa 3" = Picasa 3
"SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.6
"Spyware Doctor" = Spyware Doctor 6.1
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"UltraISO_is1" = UltraISO Premium V9.33
"Unlocker" = Unlocker 1.8.7
"WinRAR archiver" = WinRAR archiver
"Yahoo! Messenger" = Yahoo! Messenger
"Your Uninstaller! 2008_is1" = Your Uninstaller! 2008 Version 6.2

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/25/2009 3:50:16 PM | Computer Name = Kei-Lap | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18813, time stamp
0x4a6621ae, faulting module ntdll.dll, version 6.0.6002.18005, time stamp 0x49e03821,
exception code 0xc0000005, fault offset 0x000666ab, process id 0x1ad0, application
start time 0x01ca25bd41c1633e.

Error - 8/25/2009 3:50:23 PM | Computer Name = Kei-Lap | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18813, time stamp
0x4a6621ae, faulting module ntdll.dll, version 6.0.6002.18005, time stamp 0x49e03821,
exception code 0xc0000005, fault offset 0x000666ab, process id 0x129c, application
start time 0x01ca25bd4681835e.

Error - 8/25/2009 4:16:38 PM | Computer Name = Kei-Lap | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18813, time stamp
0x4a6621ae, faulting module ntdll.dll, version 6.0.6002.18005, time stamp 0x49e03821,
exception code 0xc0000005, fault offset 0x000666ab, process id 0x1ab8, application
start time 0x01ca25c0e88e9f4e.

Error - 8/25/2009 4:16:41 PM | Computer Name = Kei-Lap | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18813, time stamp
0x4a6621ae, faulting module ntdll.dll, version 6.0.6002.18005, time stamp 0x49e03821,
exception code 0xc0000005, fault offset 0x000666ab, process id 0x1b64, application
start time 0x01ca25c0f4a6a16e.

Error - 8/25/2009 4:16:54 PM | Computer Name = Kei-Lap | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18813, time stamp
0x4a6621ae, faulting module ntdll.dll, version 6.0.6002.18005, time stamp 0x49e03821,
exception code 0xc0000005, fault offset 0x000666ab, process id 0x1b98, application
start time 0x01ca25c0fc417fde.

Error - 8/25/2009 4:24:19 PM | Computer Name = Kei-Lap | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18813, time stamp
0x4a6621ae, faulting module ntdll.dll, version 6.0.6002.18005, time stamp 0x49e03821,
exception code 0xc0000005, fault offset 0x000666ab, process id 0x1480, application
start time 0x01ca25c1e3b29d4e.

Error - 8/25/2009 4:24:26 PM | Computer Name = Kei-Lap | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18813, time stamp
0x4a6621ae, faulting module ntdll.dll, version 6.0.6002.18005, time stamp 0x49e03821,
exception code 0xc0000005, fault offset 0x000666ab, process id 0x135c, application
start time 0x01ca25c207a35bee.

Error - 8/25/2009 4:25:15 PM | Computer Name = Kei-Lap | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18813, time stamp
0x4a6621ae, faulting module ntdll.dll, version 6.0.6002.18005, time stamp 0x49e03821,
exception code 0xc0000005, fault offset 0x000666ab, process id 0x1eec, application
start time 0x01ca25c221b3b8ee.

Error - 8/25/2009 4:25:19 PM | Computer Name = Kei-Lap | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18813, time stamp
0x4a6621ae, faulting module ntdll.dll, version 6.0.6002.18005, time stamp 0x49e03821,
exception code 0xc0000005, fault offset 0x000666ab, process id 0x14b4, application
start time 0x01ca25c228f8610e.

Error - 8/25/2009 5:02:24 PM | Computer Name = Kei-Lap | Source = EventSystem | ID = 4609
Description =

[ System Events ]
Error - 8/25/2009 8:37:05 PM | Computer Name = Kei-Lap | Source = netbt | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 192.168.1.192. The computer with the IP address 192.168.1.100 did
not allow the name to be claimed by this computer.

Error - 8/25/2009 8:42:15 PM | Computer Name = Kei-Lap | Source = netbt | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 192.168.1.192. The computer with the IP address 192.168.1.100 did
not allow the name to be claimed by this computer.

Error - 8/25/2009 8:47:25 PM | Computer Name = Kei-Lap | Source = netbt | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 192.168.1.192. The computer with the IP address 192.168.1.100 did
not allow the name to be claimed by this computer.

Error - 8/25/2009 8:52:35 PM | Computer Name = Kei-Lap | Source = netbt | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 192.168.1.192. The computer with the IP address 192.168.1.100 did
not allow the name to be claimed by this computer.

Error - 8/25/2009 8:57:45 PM | Computer Name = Kei-Lap | Source = netbt | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 192.168.1.192. The computer with the IP address 192.168.1.100 did
not allow the name to be claimed by this computer.

Error - 8/25/2009 9:02:55 PM | Computer Name = Kei-Lap | Source = netbt | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 192.168.1.192. The computer with the IP address 192.168.1.100 did
not allow the name to be claimed by this computer.

Error - 8/25/2009 9:08:05 PM | Computer Name = Kei-Lap | Source = netbt | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 192.168.1.192. The computer with the IP address 192.168.1.100 did
not allow the name to be claimed by this computer.

Error - 8/25/2009 9:13:15 PM | Computer Name = Kei-Lap | Source = netbt | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 192.168.1.192. The computer with the IP address 192.168.1.100 did
not allow the name to be claimed by this computer.

Error - 8/25/2009 9:18:25 PM | Computer Name = Kei-Lap | Source = netbt | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 192.168.1.192. The computer with the IP address 192.168.1.100 did
not allow the name to be claimed by this computer.

Error - 8/25/2009 9:23:35 PM | Computer Name = Kei-Lap | Source = netbt | ID = 4321
Description = The name "WORKGROUP :1d" could not be registered on the interface
with IP address 192.168.1.192. The computer with the IP address 192.168.1.100 did
not allow the name to be claimed by this computer.


< End of report >
================================================================================
==========
OTL Content


OTL logfile created on: 8/26/2009 8:28:32 AM - Run 1
OTL by OldTimer - Version 3.0.10.7 Folder = C:\Users\o0 Virgo 0o\Desktop
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18813)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.76 Gb Available Physical Memory | 87.95% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 80.02 Gb Total Space | 60.40 Gb Free Space | 75.48% Space Free | Partition Type: NTFS
Drive D: | 80.01 Gb Total Space | 34.19 Gb Free Space | 42.73% Space Free | Partition Type: NTFS
Drive E: | 128.37 Gb Total Space | 34.76 Gb Free Space | 27.08% Space Free | Partition Type: NTFS
Drive F: | 9.58 Gb Total Space | 1.66 Gb Free Space | 17.34% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: KEI-LAP
Current User Name: o0 Virgo 0o
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\STacSV.exe (IDT, Inc.)
PRC - C:\Windows\System32\Hpservice.exe (Hewlett-Packard Corporation)
PRC - C:\Windows\System32\vfsFPService.exe (Validity Sensors, Inc.)
PRC - C:\SWSetup\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.)
PRC - C:\SWSetup\DigitalPersona\Bin\DpAgent.exe (DigitalPersona, Inc.)
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe ( Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\HP\QuickPlay\QPService.exe (CyberLink Corp.)
PRC - C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe ( Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
PRC - D:\Install\Razer\Copperhead\razerhid.exe ()
PRC - C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - D:\Install\UniKey 4.0.8 Final\UniKey.exe ()
PRC - D:\Install\Razer\Copperhead\razerofa.exe (Razer Inc.)
PRC - C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\aestsrv.exe (Andrea Electronics Corporation)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - D:\Install\ESET Smart Security 4\ekrn.exe (ESET)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
PRC - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe ()
PRC - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe ()
PRC - C:\Windows\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Synaptics, Inc.)
PRC - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Windows\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe ()
PRC - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe (Hewlett-Packard)
PRC - D:\Install\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - D:\Install\Internet Download Manager 5.17\IDMan.exe (Tonec Inc.)
PRC - D:\Install\Internet Download Manager 5.17\IEMonitor.exe (Tonec Inc.)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Users\o0 Virgo 0o\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (AESTFilters [Auto | Running]) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\aestsrv.exe (Andrea Electronics Corporation)
SRV - (AgereModemAudio [Auto | Running]) – C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Com4QLBEx [On_Demand | Running]) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe (Hewlett-Packard Development Company, L.P.)
SRV - (DpHost [Auto | Running]) – C:\SWSetup\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.)
SRV - (ehRecvr [On_Demand | Stopped]) – C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) – C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [Auto | Stopped]) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (EhttpSrv [On_Demand | Stopped]) – D:\Install\ESET Smart Security 4\EHttpSrv.exe (ESET)
SRV - (ekrn [Auto | Running]) – D:\Install\ESET Smart Security 4\ekrn.exe (ESET)
SRV - (Eventlog [Auto | Running]) – C:\Windows\System32\wevtsvc.dll (Microsoft Corporation)
SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (HP Health Check Service [Auto | Running]) – c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe (Hewlett-Packard)
SRV - (hpqwmiex [On_Demand | Running]) – C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
SRV - (hpsrv [Auto | Running]) – C:\Windows\System32\Hpservice.exe (Hewlett-Packard Corporation)
SRV - (IAANTMON [Auto | Running]) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (MBAMService [Auto | Running]) – D:\Install\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (Microsoft Office Groove Audit Service [On_Demand | Stopped]) – C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NOD32FiXTemDono [Auto | Stopped]) – C:\Windows\System32\regedt32.exe (Microsoft Corporation)
SRV - (nvsvc [Auto | Running]) – C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (QPCapSvc [Auto | Running]) – C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe ()
SRV - (QPSched [Auto | Running]) – C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe ()
SRV - (sdAuxService [On_Demand | Stopped]) – D:\Install\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (sdCoreService [On_Demand | Stopped]) – D:\Install\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (STacSV [Auto | Running]) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\STacSV.exe (IDT, Inc.)
SRV - (vfsFPService [Auto | Running]) – C:\Windows\System32\vfsFPService.exe (Validity Sensors, Inc.)
SRV - (WinDefend [Disabled | Stopped]) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (Accelerometer [On_Demand | Running]) – C:\Windows\System32\DRIVERS\Accelerometer.sys (Hewlett-Packard Corporation)
DRV - (adfs [Auto | Running]) – C:\Windows\System32\drivers\adfs.sys (Adobe Systems, Inc.)
DRV - (adp94xx [Disabled | Stopped]) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (adpahci [Disabled | Stopped]) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (adpu160m [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (adpu320 [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (AgereSoftModem [On_Demand | Running]) – C:\Windows\System32\DRIVERS\AGRSM.sys (Agere Systems)
DRV - (aic78xx [Disabled | Stopped]) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (aliide [Disabled | Stopped]) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (arc [Disabled | Stopped]) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (arcsas [Disabled | Stopped]) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (AVerBDA6x [On_Demand | Running]) – C:\Windows\System32\DRIVERS\AVerBDA716x.sys (AVerMedia TECHNOLOGIES, Inc.)
DRV - (BrFiltLo [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (Brserid [Disabled | Stopped]) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrSerWdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer [On_Demand | Stopped]) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (btwaudio [On_Demand | Stopped]) – C:\Windows\System32\drivers\btwaudio.sys (Broadcom Corporation.)
DRV - (btwavdt [On_Demand | Stopped]) – C:\Windows\System32\drivers\btwavdt.sys (Broadcom Corporation.)
DRV - (btwrchid [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\btwrchid.sys (Broadcom Corporation.)
DRV - (cmdide [Disabled | Stopped]) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (E1G60 [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\E1G60I32.sys (Intel Corporation)
DRV - (eamon [Auto | Running]) – C:\Windows\System32\DRIVERS\eamon.sys (ESET)
DRV - (ehdrv [System | Running]) – C:\Windows\System32\DRIVERS\ehdrv.sys (ESET)
DRV - (elxstor [Disabled | Stopped]) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (enecir [On_Demand | Running]) – C:\Windows\System32\DRIVERS\enecir.sys (ENE TECHNOLOGY INC.)
DRV - (epfw [Auto | Running]) – C:\Windows\System32\DRIVERS\epfw.sys (ESET)
DRV - (Epfwndis [On_Demand | Running]) – C:\Windows\System32\DRIVERS\Epfwndis.sys (ESET)
DRV - (epfwwfp [Auto | Running]) – C:\Windows\System32\DRIVERS\epfwwfp.sys (ESET)
DRV - (HpCISSs [Disabled | Stopped]) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (hpdskflt [Boot | Running]) – C:\Windows\system32\DRIVERS\hpdskflt.sys (Hewlett-Packard Corporation)
DRV - (HpqKbFiltr [On_Demand | Running]) – C:\Windows\System32\DRIVERS\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (iaStor [Boot | Running]) – C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (iaStorV [Disabled | Stopped]) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (iirsp [Disabled | Stopped]) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (ISODrive [System | Running]) – D:\Install\UltraISO\drivers\ISODrive.sys (EZB Systems, Inc.)
DRV - (iteatapi [Disabled | Stopped]) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (iteraid [Disabled | Stopped]) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (JMCR [On_Demand | Running]) – C:\Windows\System32\DRIVERS\jmcr.sys (JMicron Technology Corp.)
DRV - (LSI_FC [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (LSI_SAS [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (LSI_SCSI [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (MBAMProtector [On_Demand | Running]) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (megasas [Disabled | Stopped]) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Mraid35x [Disabled | Stopped]) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (NETw5v32 [On_Demand | Running]) – C:\Windows\System32\DRIVERS\NETw5v32.sys (Intel Corporation)
DRV - (nfrd960 [Disabled | Stopped]) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (ntrigdigi [Disabled | Stopped]) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (NVHDA [On_Demand | Running]) – C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (nvlddmkm [On_Demand | Running]) – C:\Windows\System32\DRIVERS\nvlddmkm.sys (NVIDIA Corporation)
DRV - (nvraid [Disabled | Stopped]) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor [Disabled | Stopped]) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (PCTCore [Boot | Running]) – C:\Windows\system32\drivers\PCTCore.sys (PC Tools)
DRV - (ql2300 [Disabled | Stopped]) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (ql40xx [Disabled | Stopped]) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (RTL8169 [On_Demand | Running]) – C:\Windows\System32\DRIVERS\Rtlh86.sys (Realtek Corporation )
DRV - (secdrv [Auto | Running]) – C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiSRaid2 [Disabled | Stopped]) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (SiSRaid4 [Disabled | Stopped]) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (STHDA [On_Demand | Running]) – C:\Windows\System32\DRIVERS\stwrt.sys (IDT, Inc.)
DRV - (Symc8xx [Disabled | Stopped]) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_hi [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Sym_u3 [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (SynTP [On_Demand | Running]) – C:\Windows\System32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (uliahci [Disabled | Stopped]) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (UlSata [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (ulsata2 [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (UsbFltr [On_Demand | Stopped]) – C:\Windows\System32\drivers\copperhd.sys (Razer (Asia-Pacific) Pte Ltd)
DRV - (vfs101x [On_Demand | Running]) – C:\Windows\System32\drivers\vfs101x.sys (Validity Sensors, Inc.)
DRV - (viaide [Disabled | Stopped]) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (vsmraid [Disabled | Stopped]) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - ({22D78859-9CE9-4B77-BF18-AC83E81A9263} [Auto | Running]) – C:\Program Files\HP\QuickPlay\000.fcl (Cyberlink Corp.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.vn/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com.vn/"
FF - prefs.js..extensions.enabledItems: [removed]:6.3
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.2

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/08/20 06:09:07 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/08/20 06:56:21 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[removed]: D:\Install\ESET Smart Security 4\Mozilla Thunderbird

[2009/08/20 05:41:14 | 00,000,000 | —D | M] – C:\Users\o0 Virgo 0o\AppData\Roaming\mozilla\Extensions
[2009/08/20 05:41:14 | 00,000,000 | —D | M] – C:\Users\o0 Virgo 0o\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/08/20 06:04:45 | 00,000,000 | —D | M] – C:\Users\o0 Virgo 0o\AppData\Roaming\mozilla\Firefox\Profiles\hbza7uts.default\extensions
[2009/08/20 05:39:14 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/08/20 05:39:14 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/07/30 18:26:53 | 00,023,544 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/07/30 18:26:54 | 00,137,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/08/20 06:03:09 | 00,072,960 | —- | M] (Foxit Software Company) – C:\Program Files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
[2009/07/30 18:26:55 | 00,065,016 | —- | M] (mozilla.org) – C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2006/10/27 10:12:16 | 00,016,192 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL
[2008/09/11 02:56:44 | 00,144,960 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nppl3260.dll
[2008/09/11 02:37:54 | 00,094,208 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nprpjplug.dll
[2009/07/30 14:24:20 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/07/30 14:24:20 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/07/30 14:24:20 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/07/30 14:24:20 | 00,002,344 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/07/30 14:24:20 | 00,002,371 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/07/30 14:24:20 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/07/30 14:24:20 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Install\Internet Download Manager 5.17\IDMIECC.dll (Tonec Inc.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Copperhead] D:\Install\Razer\Copperhead\razerhid.exe ()
O4 - HKLM..\Run: [DpAgent] C:\SWSetup\DigitalPersona\Bin\dpagent.exe (DigitalPersona, Inc.)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe ( Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe ( Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [QPService] C:\Program Files\HP\QuickPlay\QPService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKCU..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O4 - HKCU..\Run: [UniKey] D:\Install\UniKey 4.0.8 Final\UniKey.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: BindDirectlyToPropertySetStorage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Download all links with IDM - D:\Install\Internet Download Manager 5.17\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - D:\Install\Internet Download Manager 5.17\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - D:\Install\Internet Download Manager 5.17\IEExt.htm ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Send image to &Bluetooth; Device… - C:\SWSetup\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth; Device… - C:\SWSetup\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\SWSetup\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\SWSetup\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\System32\wshbth.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/08/20 18:57:20 | 00,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{33533783-8d7f-11de-afaf-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{33533783-8d7f-11de-afaf-806e6f6e6963}\Shell\AutoRun\command - "" = G:\SETUP.EXE – File not found
O33 - MountPoints2\{33533783-8d7f-11de-afaf-806e6f6e6963}\Shell\configure\command - "" = G:\SETUP.EXE – File not found
O33 - MountPoints2\{33533783-8d7f-11de-afaf-806e6f6e6963}\Shell\install\command - "" = G:\SETUP.EXE – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/08/26 08:25:43 | 00,514,048 | —- | C] (OldTimer Tools) – C:\Users\o0 Virgo 0o\Desktop\OTL.exe
[2009/08/26 08:21:11 | 00,000,000 | —- | C] () – C:\Users\o0 Virgo 0o\Desktop\settings.dat
[2009/08/26 08:20:32 | 00,280,282 | —- | C] () – C:\Users\o0 Virgo 0o\Desktop\gmer.zip
[2009/08/26 07:14:38 | 01,674,053 | -H– | C] () – C:\Users\o0 Virgo 0o\AppData\Local\IconCache.db
[2009/08/26 04:33:44 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Local\ESET
[2009/08/26 04:06:36 | 32,182,96832 | -HS- | C] () – C:\hiberfil.sys
[2009/08/26 04:05:17 | 00,318,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CF31806.exe
[2009/08/26 04:03:46 | 00,318,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CF31506.exe
[2009/08/26 03:57:35 | 00,318,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CF30317.exe
[2009/08/26 03:57:32 | 00,000,000 | —D | C] – C:\Qoobox
[2009/08/26 03:50:02 | 00,000,000 | —D | C] – C:\Avenger
[2009/08/26 03:44:22 | 03,184,487 | R— | C] () – C:\Users\o0 Virgo 0o\Desktop\ComboFix.exe
[2009/08/26 03:35:25 | 00,731,136 | —- | C] () – C:\Users\o0 Virgo 0o\Desktop\avenger.exe
[2009/08/25 21:58:00 | 00,318,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CF25375.exe
[2009/08/25 21:50:23 | 00,046,080 | —- | C] () – C:\Users\o0 Virgo 0o\Desktop\Win32kDiag.exe
[2009/08/25 19:01:43 | 00,318,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CF23603.exe
[2009/08/25 18:55:11 | 00,318,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CF22313.exe
[2009/08/25 18:07:04 | 00,229,376 | —- | C] () – C:\Windows\PEV.exe
[2009/08/25 18:07:04 | 00,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2009/08/25 18:07:04 | 00,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2009/08/25 18:07:04 | 00,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2009/08/25 18:07:04 | 00,098,816 | —- | C] () – C:\Windows\sed.exe
[2009/08/25 18:07:04 | 00,080,412 | —- | C] () – C:\Windows\grep.exe
[2009/08/25 18:07:04 | 00,068,096 | —- | C] () – C:\Windows\zip.exe
[2009/08/25 18:07:04 | 00,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2009/08/25 18:06:51 | 00,000,000 | —D | C] – C:\Windows\ERDNT
[2009/08/25 18:06:48 | 00,318,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CF12833.exe
[2009/08/25 18:06:47 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\swsc.exe
[2009/08/25 10:33:50 | 00,472,064 | —- | C] ( ) – C:\Users\o0 Virgo 0o\Desktop\RootRepeal.exe
[2009/08/25 10:26:42 | 00,000,000 | —D | C] – C:\Windows\Minidump
[2009/08/25 10:19:24 | 00,359,932 | —- | C] () – C:\Users\o0 Virgo 0o\Desktop\dds.EXE
[2009/08/24 01:05:25 | 00,006,144 | —- | C] () – C:\Users\o0 Virgo 0o\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/24 01:02:05 | 00,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
[2009/08/22 18:28:25 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Roaming\Media Player Classic
[2009/08/21 03:20:26 | 00,005,702 | -H– | C] () – C:\Windows\nod32restoretemdono.reg
[2009/08/21 03:20:26 | 00,000,568 | -H– | C] () – C:\Windows\nod32fixtemdono.reg
[2009/08/21 03:15:56 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Roaming\ESET
[2009/08/21 03:14:03 | 00,000,000 | —D | C] – C:\ProgramData\ESET
[2009/08/21 01:09:52 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Roaming\Desktopicon
[2009/08/21 00:52:12 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Roaming\Malwarebytes
[2009/08/21 00:52:08 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/08/21 00:52:06 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/08/21 00:52:06 | 00,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2009/08/21 00:34:02 | 00,051,355 | —- | C] () – C:\Windows\System32\muzika.xm
[2009/08/21 00:29:05 | 00,159,600 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctgntdi.sys
[2009/08/21 00:29:01 | 00,130,936 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTCore.sys
[2009/08/21 00:29:01 | 00,073,840 | —- | C] (PC Tools) – C:\Windows\System32\drivers\PCTAppEvent.sys
[2009/08/21 00:28:56 | 00,064,392 | —- | C] (PC Tools) – C:\Windows\System32\drivers\pctplsg.sys
[2009/08/21 00:28:56 | 00,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2009/08/21 00:28:53 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Roaming\PC Tools
[2009/08/21 00:28:53 | 00,000,000 | —D | C] – C:\ProgramData\PC Tools
[2009/08/21 00:09:42 | 00,014,592 | —- | C] (Motorola) – C:\Windows\System32\drivers\USBICP.sys
[2009/08/21 00:09:41 | 00,069,632 | —- | C] (Razer Inc.) – C:\Windows\System32\copperhd.cpl
[2009/08/21 00:09:41 | 00,011,596 | —- | C] (Razer (Asia-Pacific) Pte Ltd) – C:\Windows\System32\drivers\copperhd.sys
[2009/08/20 23:58:24 | 00,000,000 | —D | C] – C:\ProgramData\FLEXnet
[2009/08/20 19:17:20 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\Documents\Bluetooth Exchange Folder
[2009/08/20 19:17:14 | 00,080,936 | —- | C] (Broadcom Corporation.) – C:\Windows\System32\drivers\btwavdt.sys
[2009/08/20 19:17:14 | 00,080,424 | —- | C] (Broadcom Corporation.) – C:\Windows\System32\drivers\btwaudio.sys
[2009/08/20 19:17:14 | 00,016,168 | —- | C] (Broadcom Corporation.) – C:\Windows\System32\drivers\btwrchid.sys
[2009/08/20 19:17:13 | 00,233,472 | —- | C] (Broadcom Corporation.) – C:\Windows\System32\BtwRSupport.dll
[2009/08/20 19:17:10 | 00,000,000 | —D | C] – C:\Windows\System32\es-MX
[2009/08/20 19:17:10 | 00,000,000 | —D | C] – C:\Windows\System32\es-AR
[2009/08/20 19:15:38 | 00,000,012 | —- | C] () – C:\Windows\bthservsdp.dat
[2009/08/20 19:12:10 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Roaming\DigitalPersona
[2009/08/20 19:12:10 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Local\DigitalPersona
[2009/08/20 19:05:45 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\Documents\YouCam
[2009/08/20 19:05:45 | 00,000,000 | —D | C] – C:\Program Files\Cyberlink
[2009/08/20 19:00:46 | 00,139,264 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2009/08/20 19:00:46 | 00,135,168 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2009/08/20 19:00:46 | 00,135,168 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2009/08/20 19:00:36 | 00,000,000 | —D | C] – C:\Program Files\Java
[2009/08/20 19:00:35 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2009/08/20 18:59:57 | 00,000,000 | —D | C] – C:\Windows\System32\macromed
[2009/08/20 18:59:57 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Roaming\Macromedia
[2009/08/20 18:59:15 | 00,000,281 | —- | C] () – C:\Users\Public\Documents\hpqp.ini
[2009/08/20 18:59:15 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Local\QuickPlay
[2009/08/20 18:59:09 | 00,000,000 | —D | C] – C:\ProgramData\CyberLink
[2009/08/20 18:58:48 | 01,233,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxml4.dll
[2009/08/20 18:58:48 | 00,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxml4r.dll
[2009/08/20 18:58:48 | 00,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxml4a.dll
[2009/08/20 18:58:38 | 01,060,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFC71.dll
[2009/08/20 18:58:38 | 01,047,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFC71u.dll
[2009/08/20 18:58:38 | 00,499,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msvcp71.dll
[2009/08/20 18:58:38 | 00,348,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msvcr71.dll
[2009/08/20 18:58:38 | 00,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\atl71.dll
[2009/08/20 18:57:50 | 01,560,576 | —- | C] (Hewlett-Packard Company) – C:\Windows\System32\BttnCmns_64.dll
[2009/08/20 18:57:50 | 01,560,576 | —- | C] (Hewlett-Packard Company) – C:\Windows\System32\BttnCmns.dll
[2009/08/20 18:57:50 | 01,419,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\wdfcoinstaller01005.dll
[2009/08/20 18:57:50 | 00,987,136 | —- | C] (Hewlett-Packard Company) – C:\Windows\System32\BttnCmn.dll
[2009/08/20 18:57:50 | 00,016,768 | —- | C] (Hewlett-Packard Development Company, L.P.) – C:\Windows\System32\drivers\HpqKbFiltr.sys
[2009/08/20 18:57:01 | 00,000,000 | —D | C] – C:\Program Files\Common Files\muvee Technologies
[2009/08/20 18:56:59 | 00,000,000 | —D | C] – C:\ProgramData\muvee Technologies
[2009/08/20 18:53:32 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Roaming\GTek
[2009/08/20 18:53:30 | 00,000,000 | —D | C] – C:\Program Files\HP
[2009/08/20 18:52:02 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Roaming\Macrovision
[2009/08/20 18:51:55 | 00,000,000 | —D | C] – C:\Windows\System32\tr
[2009/08/20 18:51:55 | 00,000,000 | —D | C] – C:\Windows\System32\ru
[2009/08/20 18:51:54 | 00,000,000 | —D | C] – C:\Windows\System32\ko
[2009/08/20 18:51:54 | 00,000,000 | —D | C] – C:\Windows\System32\ja
[2009/08/20 18:51:54 | 00,000,000 | —D | C] – C:\Windows\System32\it
[2009/08/20 18:51:54 | 00,000,000 | —D | C] – C:\Windows\System32\fr
[2009/08/20 18:51:54 | 00,000,000 | —D | C] – C:\Windows\System32\es
[2009/08/20 18:51:54 | 00,000,000 | —D | C] – C:\Windows\System32\de
[2009/08/20 18:51:54 | 00,000,000 | —D | C] – C:\Windows\DPDrv
[2009/08/20 18:51:53 | 00,000,000 | —D | C] – C:\ProgramData\Macrovision
[2009/08/20 18:49:29 | 00,000,000 | —D | C] – C:\ProgramData\NVIDIA
[2009/08/20 18:49:26 | 00,028,409 | —- | C] () – C:\ProgramData\nvModes.001
[2009/08/20 18:49:23 | 00,028,409 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/08/20 18:45:41 | 01,079,840 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcpluir.dll
[2009/08/20 18:45:41 | 00,768,544 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcplui.exe
[2009/08/20 18:45:41 | 00,420,384 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcpl.cpl
[2009/08/20 18:45:41 | 00,313,888 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvexpbar.dll
[2009/08/20 18:45:22 | 00,446,464 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\NVUNINST.EXE
[2009/08/20 18:45:04 | 00,934,912 | —- | C] (AVerMedia TECHNOLOGIES, Inc.) – C:\Windows\System32\drivers\AVerBDA716x.sys
[2009/08/20 18:45:04 | 00,147,877 | —- | C] (AVerMedia TECHNOLOGIES, Inc.) – C:\Windows\System32\MV716x.ax
[2009/08/20 18:45:04 | 00,003,072 | —- | C] () – C:\Windows\System32\716xCoInstaller.dll
[2009/08/20 18:45:04 | 00,000,000 | —D | C] – C:\Windows\Driver Cache
[2009/08/20 18:45:04 | 00,000,000 | —D | C] – C:\Program Files\AVerMedia
[2009/08/20 18:44:50 | 00,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_SynTP_01000.Wdf
[2009/08/20 18:44:45 | 00,000,000 | —D | C] – C:\Program Files\Synaptics
[2009/08/20 18:44:24 | 00,000,000 | —D | C] – C:\Windows\System32\ENU
[2009/08/20 18:44:23 | 01,034,776 | —- | C] (Intel Corporation) – C:\Windows\System32\imsmudlg.exe
[2009/08/20 18:44:23 | 00,319,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\difxapi.dll
[2009/08/20 18:44:23 | 00,000,000 | —D | C] – C:\Windows\System32\Lang
[2009/08/20 18:44:14 | 00,312,344 | —- | C] (Intel Corporation) – C:\Windows\System32\drivers\iaStor.sys
[2009/08/20 18:43:55 | 00,000,000 | —D | C] – C:\Windows\System32\HPMDP
[2009/08/20 18:43:55 | 00,000,000 | —D | C] – C:\Program Files\Hewlett-Packard
[2009/08/20 18:43:31 | 00,118,784 | —- | C] (Realtek Corporation ) – C:\Windows\System32\drivers\Rtlh86.sys
[2009/08/20 18:43:31 | 00,000,000 | —D | C] – C:\Program Files\Realtek
[2009/08/20 18:43:29 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Roaming\InstallShield
[2009/08/20 18:43:05 | 00,054,824 | —- | C] (Agere Systems) – C:\Windows\System32\agrsmdel.exe
[2009/08/20 18:42:59 | 00,000,000 | —D | C] – C:\Windows\Options
[2009/08/20 18:42:59 | 00,000,000 | —D | C] – C:\SWSetup
[2009/08/20 18:42:52 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Roaming\Hewlett Packard
[2009/08/20 18:42:10 | 00,000,000 | —D | C] – C:\Program Files\Validity Sensors, Inc
[2009/08/20 18:42:07 | 00,000,000 | -HSD | C] – C:\Windows\Installer
[2009/08/20 18:41:58 | 00,000,251 | —- | C] () – C:\Windows\xUninstall.bat
[2009/08/20 18:41:54 | 00,015,086 | —- | C] () – C:\Windows\System32\jmcr_xd.ico
[2009/08/20 18:41:54 | 00,015,086 | —- | C] () – C:\Windows\System32\jmcr_ms.ico
[2009/08/20 18:41:54 | 00,015,086 | —- | C] () – C:\Windows\System32\jmcr_mmc.ico
[2009/08/20 18:41:54 | 00,000,000 | —D | C] – C:\Windows\JMCR_DIR
[2009/08/20 18:40:39 | 00,053,248 | —- | C] (Windows XP Bundled build C-Centric Single User) – C:\Windows\System32\CSVer.dll
[2009/08/20 18:40:39 | 00,000,000 | —D | C] – C:\Program Files\Intel
[2009/08/20 18:39:49 | 05,611,585 | —- | C] (IDT, Inc.) – C:\Windows\System32\idtcpl.cpl
[2009/08/20 18:39:49 | 02,387,968 | —- | C] (IDT, Inc.) – C:\Windows\System32\stlang.dll
[2009/08/20 18:39:49 | 00,512,000 | —- | C] (IDT, Inc.) – C:\Windows\System32\idtmini1.exe
[2009/08/20 18:39:49 | 00,442,433 | —- | C] (IDT, Inc.) – C:\Windows\sttray.exe
[2009/08/20 18:39:49 | 00,372,736 | —- | C] (Andrea Electronics Corporation) – C:\Windows\System32\aestecap.dll
[2009/08/20 18:39:49 | 00,133,632 | —- | C] (Andrea Electronics Corporation) – C:\Windows\System32\aestacap.dll
[2009/08/20 18:39:49 | 00,073,728 | —- | C] (Andrea Electronics Corporation) – C:\Windows\System32\AESTCom.dll
[2009/08/20 18:39:49 | 00,053,248 | —- | C] (Andrea Electronics Corporation) – C:\Windows\System32\aestaren.dll
[2009/08/20 18:39:49 | 00,015,222 | —- | C] () – C:\Windows\System32\nbspkrs.ico
[2009/08/20 18:39:49 | 00,003,774 | —- | C] () – C:\Windows\System32\bltinmic.ico
[2009/08/20 18:39:49 | 00,003,774 | —- | C] () – C:\Windows\System32\2hps.ico
[2009/08/20 18:39:41 | 00,164,352 | —- | C] (IDT, Inc.) – C:\Windows\System32\staco.dll
[2009/08/20 18:39:35 | 00,676,352 | —- | C] (IDT, Inc.) – C:\Windows\System32\stapo.dll
[2009/08/20 18:39:35 | 00,404,992 | —- | C] (IDT, Inc.) – C:\Windows\System32\stapi32.dll
[2009/08/20 18:39:35 | 00,378,368 | —- | C] (IDT, Inc.) – C:\Windows\System32\drivers\stwrt.sys
[2009/08/20 18:39:35 | 00,344,576 | —- | C] (IDT, Inc.) – C:\Windows\System32\stcplx.dll
[2009/08/20 18:39:31 | 00,000,000 | -H-D | C] – C:\Program Files\InstallShield Installation Information
[2009/08/20 18:39:31 | 00,000,000 | —D | C] – C:\Program Files\IDT
[2009/08/20 18:39:29 | 00,000,000 | —D | C] – C:\Program Files\Common Files\InstallShield
[2009/08/20 16:45:41 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Local\Yahoo
[2009/08/20 08:00:20 | 00,000,000 | —D | C] – C:\Program Files\Adobe Media Player
[2009/08/20 07:59:21 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2009/08/20 07:59:03 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Local\Adobe
[2009/08/20 07:58:42 | 00,000,000 | —D | C] – C:\Program Files\Adobe
[2009/08/20 07:58:25 | 00,000,000 | —D | C] – C:\ProgramData\Adobe
[2009/08/20 07:57:42 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Macrovision Shared
[2009/08/20 07:56:13 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2009/08/20 07:38:49 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Roaming\Adobe
[2009/08/20 07:06:12 | 00,000,000 | —D | C] – C:\ProgramData\Yahoo!
[2009/08/20 07:06:11 | 00,000,000 | —D | C] – C:\Program Files\Yahoo!
[2009/08/20 06:57:10 | 00,032,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msonpmon.dll
[2009/08/20 06:56:10 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Works
[2009/08/20 06:55:56 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio
[2009/08/20 06:55:56 | 00,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER
[2009/08/20 06:55:37 | 00,000,000 | —D | C] – C:\Windows\PCHEALTH
[2009/08/20 06:55:37 | 00,000,000 | —D | C] – C:\Program Files\Microsoft.NET
[2009/08/20 06:50:59 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio 8
[2009/08/20 06:50:20 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Local\Microsoft Help
[2009/08/20 06:50:18 | 00,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2009/08/20 06:50:18 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2009/08/20 06:41:43 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\Documents\Downloads
[2009/08/20 06:41:43 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Roaming\IDM
[2009/08/20 06:41:43 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Roaming\DMCache
[2009/08/20 06:38:37 | 00,000,000 | —D | C] – C:\Program Files\Common Files\PX Storage Engine
[2009/08/20 06:38:26 | 00,000,000 | —D | C] – C:\Windows\System32\IOSUBSYS
[2009/08/20 06:38:26 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Local\Google
[2009/08/20 06:38:26 | 00,000,000 | —D | C] – C:\Program Files\Google
[2009/08/20 06:26:16 | 00,000,000 | —D | C] – C:\Windows\Lhsp
[2009/08/20 06:26:05 | 00,000,000 | —D | C] – C:\ProgramData\InstallShield
[2009/08/20 06:26:04 | 00,058,368 | —- | C] (Deskperience) – C:\Windows\System32\TCaptureX.dll
[2009/08/20 06:26:02 | 00,385,100 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Msvcrtd.dll
[2009/08/20 06:26:02 | 00,098,304 | —- | C] (Deskperience) – C:\Windows\System32\TCapture.dll
[2009/08/20 06:26:02 | 00,027,648 | —- | C] (Deskperience) – C:\Windows\System32\RL.dll
[2009/08/20 06:26:02 | 00,007,168 | —- | C] (Deskperience) – C:\Windows\System32\TCCustom.dll
[2009/08/20 06:15:09 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Roaming\MTD
[2009/08/20 06:11:31 | 00,000,000 | —D | C] – C:\Program Files\Common Files\MSSoap
[2009/08/20 06:11:30 | 00,000,000 | —D | C] – C:\Program Files\Common Files\L&H;
[2009/08/20 06:09:06 | 00,278,528 | —- | C] (Real Networks, Inc) – C:\Windows\System32\pncrt.dll
[2009/08/20 06:09:06 | 00,185,920 | —- | C] (RealNetworks, Inc.) – C:\Windows\System32\rmoc3260.dll
[2009/08/20 06:09:06 | 00,168,448 | —- | C] () – C:\Windows\System32\unrar.dll
[2009/08/20 06:09:06 | 00,006,656 | —- | C] (RealNetworks, Inc.) – C:\Windows\System32\pndx5016.dll
[2009/08/20 06:09:06 | 00,005,632 | —- | C] (RealNetworks, Inc.) – C:\Windows\System32\pndx5032.dll
[2009/08/20 06:09:06 | 00,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2009/08/20 06:09:05 | 00,881,664 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2009/08/20 06:09:05 | 00,839,680 | —- | C] (http://www.mp3dev.org/) – C:\Windows\System32\lameACM.acm
[2009/08/20 06:09:05 | 00,217,088 | —- | C] (www.helixcommunity.org) – C:\Windows\System32\yv12vfw.dll
[2009/08/20 06:09:05 | 00,205,824 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2009/08/20 06:09:05 | 00,118,784 | —- | C] (fccHandler) – C:\Windows\System32\ac3acm.acm
[2009/08/20 06:09:05 | 00,000,414 | —- | C] () – C:\Windows\System32\lame_acm.xml
[2009/08/20 06:09:04 | 03,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2009/08/20 06:09:04 | 00,685,056 | —- | C] (DivX, Inc.) – C:\Windows\System32\divx.dll
[2009/08/20 06:09:04 | 00,090,112 | —- | C] (DivX, Inc.) – C:\Windows\System32\dpl100.dll
[2009/08/20 06:09:04 | 00,085,504 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2009/08/20 06:09:04 | 00,060,273 | —- | C] (Open Source Software community project) – C:\Windows\System32\pthreadGC2.dll
[2009/08/20 06:09:04 | 00,000,547 | —- | C] () – C:\Windows\System32\ff_vfw.dll.manifest
[2009/08/20 06:04:09 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Roaming\Foxit
[2009/08/20 06:02:04 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Local\Hewlett-Packard
[2009/08/20 05:57:25 | 00,000,000 | —D | C] – C:\Program Files\Common Files\EZB Systems
[2009/08/20 05:57:24 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\Documents\My ISO Files
[2009/08/20 05:56:52 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Roaming\WinRAR
[2009/08/20 05:47:45 | 01,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/08/20 05:47:45 | 00,594,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/08/20 05:47:45 | 00,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\occache.dll
[2009/08/20 05:47:45 | 00,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2009/08/20 05:47:45 | 00,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2009/08/20 05:47:45 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2009/08/20 05:47:45 | 00,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2009/08/20 05:47:45 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/08/20 05:47:44 | 01,985,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iertutil.dll
[2009/08/20 05:47:44 | 01,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2009/08/20 05:47:44 | 01,208,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\urlmon.dll
[2009/08/20 05:47:44 | 00,915,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wininet.dll
[2009/08/20 05:47:44 | 00,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2009/08/20 05:47:44 | 00,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2009/08/20 05:47:44 | 00,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2009/08/20 05:47:44 | 00,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2009/08/20 05:47:44 | 00,057,667 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2009/08/20 05:47:44 | 00,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2009/08/20 05:47:44 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2009/08/20 05:47:43 | 11,067,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieframe.dll
[2009/08/20 05:47:43 | 05,937,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.dll
[2009/08/20 05:45:54 | 00,348,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2009/08/20 05:45:54 | 00,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2009/08/20 05:45:54 | 00,156,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2009/08/20 05:45:54 | 00,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2009/08/20 05:45:54 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2009/08/20 05:45:54 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tdc.ocx
[2009/08/20 05:45:54 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmled.dll
[2009/08/20 05:45:54 | 00,059,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardie.dll
[2009/08/20 05:45:54 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2009/08/20 05:45:54 | 00,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2009/08/20 05:45:54 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\corpol.dll
[2009/08/20 05:45:53 | 00,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2009/08/20 05:45:53 | 00,236,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webcheck.dll
[2009/08/20 05:45:53 | 00,229,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2009/08/20 05:45:53 | 00,208,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinFXDocObj.exe
[2009/08/20 05:45:53 | 00,193,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2009/08/20 05:45:53 | 00,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2009/08/20 05:45:53 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2009/08/20 05:45:53 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2009/08/20 05:45:53 | 00,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2009/08/20 05:45:52 | 00,726,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2009/08/20 05:45:52 | 00,445,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2009/08/20 05:45:52 | 00,420,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2009/08/20 05:45:52 | 00,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2009/08/20 05:45:52 | 00,128,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\advpack.dll
[2009/08/20 05:45:52 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2009/08/20 05:45:52 | 00,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2009/08/20 05:45:51 | 03,698,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2009/08/20 05:45:51 | 00,169,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2009/08/20 05:45:51 | 00,109,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PDMSetup.exe
[2009/08/20 05:45:51 | 00,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2009/08/20 05:45:51 | 00,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2009/08/20 05:45:51 | 00,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetDepNx.exe
[2009/08/20 05:45:51 | 00,045,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshta.exe
[2009/08/20 05:39:19 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Roaming\Mozilla
[2009/08/20 05:39:19 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Local\Mozilla
[2009/08/20 05:39:19 | 00,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2009/08/20 05:39:14 | 00,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2009/08/20 05:37:58 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Roaming\URSoft
[2009/08/20 05:37:58 | 00,000,000 | —D | C] – C:\ProgramData\TEMP
[2009/08/16 10:55:03 | 00,000,000 | —D | C] – C:\Windows\System32\vi-VN
[2009/08/16 10:55:03 | 00,000,000 | —D | C] – C:\Windows\System32\eu-ES
[2009/08/16 10:55:03 | 00,000,000 | —D | C] – C:\Windows\System32\ca-ES
[2009/08/16 10:52:46 | 00,000,000 | —D | C] – C:\Windows\System32\SPReview
[2009/08/16 10:47:00 | 00,928,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scavenge.dll
[2009/08/16 10:46:53 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\compcln.exe
[2009/08/16 10:44:24 | 01,169,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdclt.exe
[2009/08/16 10:44:24 | 00,784,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rpcrt4.dll
[2009/08/16 10:44:24 | 00,550,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rpcss.dll
[2009/08/16 10:44:24 | 00,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_isv.exe
[2009/08/16 10:44:24 | 00,518,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate.exe
[2009/08/16 10:44:24 | 00,476,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_isv.dll
[2009/08/16 10:44:24 | 00,472,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc.dll
[2009/08/16 10:44:24 | 00,466,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\riched20.dll
[2009/08/16 10:44:24 | 00,441,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SearchIndexer.exe
[2009/08/16 10:44:24 | 00,347,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp.exe
[2009/08/16 10:44:24 | 00,346,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp_isv.exe
[2009/08/16 10:44:24 | 00,324,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdohlp.dll
[2009/08/16 10:44:24 | 00,241,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rsaenh.dll
[2009/08/16 10:44:24 | 00,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SearchProtocolHost.exe
[2009/08/16 10:44:24 | 00,172,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scrrun.dll
[2009/08/16 10:44:24 | 00,152,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp_isv.dll
[2009/08/16 10:44:24 | 00,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp.dll
[2009/08/16 10:44:24 | 00,127,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rpchttp.dll
[2009/08/16 10:44:24 | 00,113,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rmcast.sys
[2009/08/16 10:44:24 | 00,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\sdbus.sys
[2009/08/16 10:44:24 | 00,087,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SearchFilterHost.exe
[2009/08/16 10:44:24 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secur32.dll
[2009/08/16 10:44:24 | 00,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\samlib.dll
[2009/08/16 10:44:24 | 00,053,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rrinstaller.exe
[2009/08/16 10:44:24 | 00,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rtffilt.dll
[2009/08/16 10:44:24 | 00,036,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rtutils.dll
[2009/08/16 10:44:24 | 00,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\RNDISMP.sys
[2009/08/16 10:44:24 | 00,020,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rwinsta.exe
[2009/08/16 10:44:23 | 00,595,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\schedsvc.dll
[2009/08/16 10:44:23 | 00,483,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\samsrv.dll
[2009/08/16 10:44:23 | 00,413,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scrptadm.dll
[2009/08/16 10:44:23 | 00,306,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scesrv.dll
[2009/08/16 10:44:23 | 00,268,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\schannel.dll
[2009/08/16 10:44:23 | 00,245,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scansetting.dll
[2009/08/16 10:44:23 | 00,180,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scrobj.dll
[2009/08/16 10:44:23 | 00,177,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scecli.dll
[2009/08/16 10:44:23 | 00,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\scksp.dll
[2009/08/16 10:44:23 | 00,095,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SCardSvr.dll
[2009/08/16 10:44:22 | 01,823,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pnidui.dll
[2009/08/16 10:44:22 | 01,248,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PerfCenterCPL.dll
[2009/08/16 10:44:22 | 01,107,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pidgenx.dll
[2009/08/16 10:44:22 | 00,723,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\powercpl.dll
[2009/08/16 10:44:22 | 00,704,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PhotoScreensaver.scr
[2009/08/16 10:44:22 | 00,644,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\p2psvc.dll
[2009/08/16 10:44:22 | 00,542,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pnpui.dll
[2009/08/16 10:44:22 | 00,464,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pcaui.dll
[2009/08/16 10:44:22 | 00,425,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PhotoMetadataHandler.dll
[2009/08/16 10:44:22 | 00,327,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\P2PGraph.dll
[2009/08/16 10:44:22 | 00,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\photowiz.dll
[2009/08/16 10:44:22 | 00,242,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pdh.dll
[2009/08/16 10:44:22 | 00,241,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceApi.dll
[2009/08/16 10:44:22 | 00,181,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pnpsetup.dll
[2009/08/16 10:44:22 | 00,167,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\portcls.sys
[2009/08/16 10:44:22 | 00,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceTypes.dll
[2009/08/16 10:44:22 | 00,149,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\pci.sys
[2009/08/16 10:44:22 | 00,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PkgMgr.exe
[2009/08/16 10:44:22 | 00,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\phon.ime
[2009/08/16 10:44:22 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceClassExtension.dll
[2009/08/16 10:44:22 | 00,072,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\pacer.sys
[2009/08/16 10:44:22 | 00,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PNPXAssoc.dll
[2009/08/16 10:44:22 | 00,058,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PnPUnattend.exe
[2009/08/16 10:44:22 | 00,054,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\partmgr.sys
[2009/08/16 10:44:22 | 00,043,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\pciidex.sys
[2009/08/16 10:44:22 | 00,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PnPutil.exe
[2009/08/16 10:44:22 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\perfdisk.dll
[2009/08/16 10:44:21 | 12,240,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0007.dll
[2009/08/16 10:44:21 | 03,601,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2009/08/16 10:44:21 | 03,549,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2009/08/16 10:44:21 | 02,644,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsLexicons0009.dll
[2009/08/16 10:44:21 | 02,153,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oobefldr.dll
[2009/08/16 10:44:21 | 01,541,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\onex.dll
[2009/08/16 10:44:21 | 01,381,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Query.dll
[2009/08/16 10:44:21 | 01,316,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ole32.dll
[2009/08/16 10:44:21 | 01,314,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quartz.dll
[2009/08/16 10:44:21 | 01,202,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntdll.dll
[2009/08/16 10:44:21 | 01,083,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ntfs.sys
[2009/08/16 10:44:21 | 00,880,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RacEngn.dll
[2009/08/16 10:44:21 | 00,825,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasdlg.dll
[2009/08/16 10:44:21 | 00,758,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qmgr.dll
[2009/08/16 10:44:21 | 00,642,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasgcw.dll
[2009/08/16 10:44:21 | 00,563,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleaut32.dll
[2009/08/16 10:44:21 | 00,556,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pmcsnap.dll
[2009/08/16 10:44:21 | 00,505,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qedit.dll
[2009/08/16 10:44:21 | 00,409,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbc32.dll
[2009/08/16 10:44:21 | 00,392,170 | —- | C] () – C:\Windows\System32\onex.tmf
[2009/08/16 10:44:21 | 00,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasplap.dll
[2009/08/16 10:44:21 | 00,340,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RelMon.dll
[2009/08/16 10:44:21 | 00,286,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasapi32.dll
[2009/08/16 10:44:21 | 00,281,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\raschap.dll
[2009/08/16 10:44:21 | 00,262,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasmans.dll
[2009/08/16 10:44:21 | 00,259,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasppp.dll
[2009/08/16 10:44:21 | 00,244,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rastls.dll
[2009/08/16 10:44:21 | 00,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntprint.dll
[2009/08/16 10:44:21 | 00,194,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\offfilt.dll
[2009/08/16 10:44:21 | 00,182,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\osk.exe
[2009/08/16 10:44:21 | 00,155,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasmontr.dll
[2009/08/16 10:44:21 | 00,148,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rfcomm.sys
[2009/08/16 10:44:21 | 00,148,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\nwifi.sys
[2009/08/16 10:44:21 | 00,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nlhtml.dll
[2009/08/16 10:44:21 | 00,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quick.ime
[2009/08/16 10:44:21 | 00,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qintlgnt.ime
[2009/08/16 10:44:21 | 00,121,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntmarta.dll
[2009/08/16 10:44:21 | 00,114,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbccp32.dll
[2009/08/16 10:44:21 | 00,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\regsvc.dll
[2009/08/16 10:44:21 | 00,097,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleprn.dll
[2009/08/16 10:44:21 | 00,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pintlgnt.ime
[2009/08/16 10:44:21 | 00,088,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\olepro32.dll
[2009/08/16 10:44:21 | 00,082,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nslookup.exe
[2009/08/16 10:44:21 | 00,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rastapi.dll
[2009/08/16 10:44:21 | 00,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rassstp.sys
[2009/08/16 10:44:21 | 00,062,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ohci1394.sys
[2009/08/16 10:44:21 | 00,052,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasdiag.dll
[2009/08/16 10:44:21 | 00,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rekeywiz.exe
[2009/08/16 10:44:21 | 00,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\raspppoe.sys
[2009/08/16 10:44:21 | 00,040,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbcconf.dll
[2009/08/16 10:44:21 | 00,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ocsetup.exe
[2009/08/16 10:44:21 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\npfs.sys
[2009/08/16 10:44:21 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qprocess.exe
[2009/08/16 10:44:21 | 00,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasdial.exe
[2009/08/16 10:44:21 | 00,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\reset.exe
[2009/08/16 10:44:21 | 00,014,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\query.exe
[2009/08/16 10:44:21 | 00,009,212 | —- | C] () – C:\Windows\System32\RacUR.xml
[2009/08/16 10:44:21 | 00,000,153 | —- | C] () – C:\Windows\System32\RacUREx.xml
[2009/08/16 10:44:20 | 00,869,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printui.dll
[2009/08/16 10:44:20 | 00,779,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationNative_v0300.dll
[2009/08/16 10:44:20 | 00,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2009/08/16 10:44:20 | 00,612,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpencom.dll
[2009/08/16 10:44:20 | 00,551,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\prnntfy.dll
[2009/08/16 10:44:20 | 00,323,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2009/08/16 10:44:20 | 00,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rdpdr.sys
[2009/08/16 10:44:20 | 00,225,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rdbss.sys
[2009/08/16 10:44:20 | 00,180,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rdpwd.sys
[2009/08/16 10:44:20 | 00,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpclip.exe
[2009/08/16 10:44:20 | 00,167,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationSettings.exe
[2009/08/16 10:44:20 | 00,107,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpwsx.dll
[2009/08/16 10:44:20 | 00,102,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2009/08/16 10:44:20 | 00,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\powrprof.dll
[2009/08/16 10:44:20 | 00,091,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpendp.dll
[2009/08/16 10:44:20 | 00,067,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\regapi.dll
[2009/08/16 10:44:20 | 00,062,976 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2009/08/16 10:44:20 | 00,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\reg.exe
[2009/08/16 10:44:20 | 00,041,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2009/08/16 10:44:20 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2009/08/16 10:44:19 | 00,754,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\propsys.dll
[2009/08/16 10:44:19 | 00,497,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qdvd.dll
[2009/08/16 10:44:19 | 00,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\QAGENTRT.DLL
[2009/08/16 10:44:19 | 00,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2009/08/16 10:44:19 | 00,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2009/08/16 10:44:19 | 00,166,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\puiapi.dll
[2009/08/16 10:44:19 | 00,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\profsvc.dll
[2009/08/16 10:44:19 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\propdefs.dll
[2009/08/16 10:44:19 | 00,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sendmail.dll
[2009/08/16 10:44:19 | 00,050,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PSHED.DLL
[2009/08/16 10:44:19 | 00,021,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qappsrv.exe
[2009/08/16 10:44:18 | 11,584,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shell32.dll
[2009/08/16 10:44:18 | 01,591,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\setupapi.dll
[2009/08/16 10:44:18 | 01,068,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shdocvw.dll
[2009/08/16 10:44:18 | 00,627,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sethc.exe
[2009/08/16 10:44:18 | 00,353,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shlwapi.dll
[2009/08/16 10:44:18 | 00,279,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\services.exe
[2009/08/16 10:44:18 | 00,020,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shadow.exe
[2009/08/16 10:44:16 | 00,344,698 | —- | C] () – C:\Windows\System32\eaphost.tmf
[2009/08/16 10:44:16 | 00,187,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eapp3hst.dll
[2009/08/16 10:44:16 | 00,183,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eapphost.dll
[2009/08/16 10:44:16 | 00,141,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ecache.sys
[2009/08/16 10:44:16 | 00,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eappcfg.dll
[2009/08/16 10:44:16 | 00,093,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eappgnui.dll
[2009/08/16 10:44:15 | 02,926,592 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2009/08/16 10:44:15 | 02,092,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dfsr.exe
[2009/08/16 10:44:15 | 01,459,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\esent.dll
[2009/08/16 10:44:15 | 01,078,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\diagperf.dll
[2009/08/16 10:44:15 | 00,978,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drmv2clt.dll
[2009/08/16 10:44:15 | 00,626,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\dxgkrnl.sys
[2009/08/16 10:44:15 | 00,564,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\emdmgmt.dll
[2009/08/16 10:44:15 | 00,561,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\hdaudbus.sys
[2009/08/16 10:44:15 | 00,485,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\evr.dll
[2009/08/16 10:44:15 | 00,444,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dsound.dll
[2009/08/16 10:44:15 | 00,442,788 | —- | C] () – C:\Windows\System32\dot3.tmf
[2009/08/16 10:44:15 | 00,428,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2009/08/16 10:44:15 | 00,407,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpapimig.exe
[2009/08/16 10:44:15 | 00,378,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\devmgr.dll
[2009/08/16 10:44:15 | 00,284,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drmmgrtn.dll
[2009/08/16 10:44:15 | 00,268,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\es.dll
[2009/08/16 10:44:15 | 00,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drvstore.dll
[2009/08/16 10:44:15 | 00,236,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\HdAudio.sys
[2009/08/16 10:44:15 | 00,230,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\diskraid.exe
[2009/08/16 10:44:15 | 00,205,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eudcedit.exe
[2009/08/16 10:44:15 | 00,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dhcpcsvc.dll
[2009/08/16 10:44:15 | 00,194,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drvinst.exe
[2009/08/16 10:44:15 | 00,175,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dot3svc.dll
[2009/08/16 10:44:15 | 00,168,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnsapi.dll
[2009/08/16 10:44:15 | 00,137,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dsprop.dll
[2009/08/16 10:44:15 | 00,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\exfat.sys
[2009/08/16 10:44:15 | 00,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dhcpcsvc6.dll
[2009/08/16 10:44:15 | 00,128,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpresult.exe
[2009/08/16 10:44:15 | 00,120,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EhStorAPI.dll
[2009/08/16 10:44:15 | 00,119,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\diskpart.exe
[2009/08/16 10:44:15 | 00,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/08/16 10:44:15 | 00,114,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EhStorShell.dll
[2009/08/16 10:44:15 | 00,105,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dmsynth.dll
[2009/08/16 10:44:15 | 00,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dmusic.dll
[2009/08/16 10:44:15 | 00,093,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dfshim.dll
[2009/08/16 10:44:15 | 00,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnsrslvr.dll
[2009/08/16 10:44:15 | 00,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dwm.exe
[2009/08/16 10:44:15 | 00,076,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\dxg.sys
[2009/08/16 10:44:15 | 00,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\dfsc.sys
[2009/08/16 10:44:15 | 00,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dot3msm.dll
[2009/08/16 10:44:15 | 00,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dimsroam.dll
[2009/08/16 10:44:15 | 00,053,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\disk.sys
[2009/08/16 10:44:15 | 00,049,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dot3cfg.dll
[2009/08/16 10:44:15 | 00,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\hbaapi.dll
[2009/08/16 10:44:15 | 00,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EhStorPwdMgr.dll
[2009/08/16 10:44:15 | 00,029,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpprnext.dll
[2009/08/16 10:44:15 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpscript.dll
[2009/08/16 10:44:15 | 00,027,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Dumpata.sys
[2009/08/16 10:44:15 | 00,020,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ExplorerFrame.dll
[2009/08/16 10:44:15 | 00,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Diskdump.sys
[2009/08/16 10:44:15 | 00,007,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\f3ahvoas.dll
[2009/08/16 10:44:15 | 00,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxmasf.dll
[2009/08/16 10:44:14 | 00,576,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpsvc.dll
[2009/08/16 10:44:14 | 00,463,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IasMigReader.exe
[2009/08/16 10:44:14 | 00,454,144 | —- | C] (Microsoft) – C:\Windows\System32\IasMigPlugin.dll
[2009/08/16 10:44:14 | 00,401,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\http.sys
[2009/08/16 10:44:14 | 00,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasnap.dll
[2009/08/16 10:44:14 | 00,080,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\hdwwiz.exe
[2009/08/16 10:44:14 | 00,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iashlpr.dll
[2009/08/16 10:44:14 | 00,058,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasacct.dll
[2009/08/16 10:44:14 | 00,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasads.dll
[2009/08/16 10:44:14 | 00,047,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasdatastore.dll
[2009/08/16 10:44:14 | 00,039,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\hidclass.sys
[2009/08/16 10:44:14 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\hidserv.dll
[2009/08/16 10:44:14 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpscript.exe
[2009/08/16 10:44:14 | 00,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpupdate.exe
[2009/08/16 10:44:14 | 00,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\hidusb.sys
[2009/08/16 10:44:13 | 02,134,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FunctionDiscoveryFolder.dll
[2009/08/16 10:44:13 | 01,985,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\authui.dll
[2009/08/16 10:44:13 | 01,696,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gameux.dll
[2009/08/16 10:44:13 | 01,216,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AuxiliaryDisplayCpl.dll
[2009/08/16 10:44:13 | 00,950,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpedit.dll
[2009/08/16 10:44:13 | 00,780,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fveui.dll
[2009/08/16 10:44:13 | 00,735,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fvecpl.dll
[2009/08/16 10:44:13 | 00,656,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\autoconv.exe
[2009/08/16 10:44:13 | 00,643,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\autochk.exe
[2009/08/16 10:44:13 | 00,636,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\autofmt.exe
[2009/08/16 10:44:13 | 00,595,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FWPUCLNT.DLL
[2009/08/16 10:44:13 | 00,516,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\autoplay.dll
[2009/08/16 10:44:13 | 00,315,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\audiosrv.dll
[2009/08/16 10:44:13 | 00,297,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gdi32.dll
[2009/08/16 10:44:13 | 00,289,792 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2009/08/16 10:44:13 | 00,196,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fsquirt.exe
[2009/08/16 10:44:13 | 00,190,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\fltMgr.sys
[2009/08/16 10:44:13 | 00,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fveapi.dll
[2009/08/16 10:44:13 | 00,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fundisc.dll
[2009/08/16 10:44:13 | 00,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Faultrep.dll
[2009/08/16 10:44:13 | 00,143,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\fvevol.sys
[2009/08/16 10:44:13 | 00,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\fastfat.sys
[2009/08/16 10:44:13 | 00,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontext.dll
[2009/08/16 10:44:13 | 00,115,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AudioSes.dll
[2009/08/16 10:44:13 | 00,115,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AuxiliaryDisplayDriverLib.dll
[2009/08/16 10:44:13 | 00,109,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ataport.sys
[2009/08/16 10:44:13 | 00,102,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AuxiliaryDisplayServices.dll
[2009/08/16 10:44:13 | 00,099,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\FWPKCLNT.SYS
[2009/08/16 10:44:13 | 00,088,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\audiodg.exe
[2009/08/16 10:44:13 | 00,088,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdBth.dll
[2009/08/16 10:44:13 | 00,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\authz.dll
[2009/08/16 10:44:13 | 00,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gpapi.dll
[2009/08/16 10:44:13 | 00,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdWCN.dll
[2009/08/16 10:44:13 | 00,068,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdSSDP.dll
[2009/08/16 10:44:13 | 00,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdWSD.dll
[2009/08/16 10:44:13 | 00,060,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\findstr.exe
[2009/08/16 10:44:13 | 00,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\feclient.dll
[2009/08/16 10:44:13 | 00,053,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdeploy.dll
[2009/08/16 10:44:13 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ftp.exe
[2009/08/16 10:44:13 | 00,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2009/08/16 10:44:13 | 00,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FwRemoteSvr.dll
[2009/08/16 10:44:13 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdProxy.dll
[2009/08/16 10:44:13 | 00,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fc.exe
[2009/08/16 10:44:13 | 00,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdBthProxy.dll
[2009/08/16 10:44:12 | 02,515,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\accessibilitycpl.dll
[2009/08/16 10:44:12 | 01,342,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\brcpl.dll
[2009/08/16 10:44:12 | 01,324,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\browseui.dll
[2009/08/16 10:44:12 | 00,757,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\azroles.dll
[2009/08/16 10:44:12 | 00,542,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\blackbox.dll
[2009/08/16 10:44:12 | 00,438,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\brcplsiw.dll
[2009/08/16 10:44:12 | 00,334,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\BFE.DLL
[2009/08/16 10:44:12 | 00,274,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bcrypt.dll
[2009/08/16 10:44:12 | 00,265,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\acpi.sys
[2009/08/16 10:44:12 | 00,130,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\basecsp.dll
[2009/08/16 10:44:12 | 00,093,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\bridge.sys
[2009/08/16 10:44:12 | 00,045,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bthci.dll
[2009/08/16 10:44:12 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bitsigd.dll
[2009/08/16 10:44:12 | 00,022,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\bthenum.sys
[2009/08/16 10:44:12 | 00,019,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\atapi.sys
[2009/08/16 10:44:11 | 01,856,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dbgeng.dll
[2009/08/16 10:44:11 | 01,730,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\apds.dll
[2009/08/16 10:44:11 | 01,645,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\connect.dll
[2009/08/16 10:44:11 | 01,209,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\comsvcs.dll
[2009/08/16 10:44:11 | 01,122,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\appwiz.cpl
[2009/08/16 10:44:11 | 00,978,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\crypt32.dll
[2009/08/16 10:44:11 | 00,800,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\advapi32.dll
[2009/08/16 10:44:11 | 00,617,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\adtschema.dll
[2009/08/16 10:44:11 | 00,593,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\comuid.dll
[2009/08/16 10:44:11 | 00,481,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmdial32.dll
[2009/08/16 10:44:11 | 00,450,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\comdlg32.dll
[2009/08/16 10:44:11 | 00,273,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\afd.sys
[2009/08/16 10:44:11 | 00,199,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\adsldpc.dll
[2009/08/16 10:44:11 | 00,178,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\credui.dll
[2009/08/16 10:44:11 | 00,171,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\apphelp.dll
[2009/08/16 10:44:11 | 00,148,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\appmgmts.dll
[2009/08/16 10:44:11 | 00,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\aaclient.dll
[2009/08/16 10:44:11 | 00,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\adsmsext.dll
[2009/08/16 10:44:11 | 00,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\conime.exe
[2009/08/16 10:44:11 | 00,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmmon32.exe
[2009/08/16 10:44:11 | 00,035,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\crashdmp.sys
[2009/08/16 10:44:11 | 00,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2009/08/16 10:44:10 | 06,103,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\chtbrkr.dll
[2009/08/16 10:44:10 | 01,788,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d9.dll
[2009/08/16 10:44:10 | 01,671,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\chsbrkr.dll
[2009/08/16 10:44:10 | 01,502,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certmgr.dll
[2009/08/16 10:44:10 | 01,112,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CertEnroll.dll
[2009/08/16 10:44:10 | 00,971,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cryptui.dll
[2009/08/16 10:44:10 | 00,640,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bthprops.cpl
[2009/08/16 10:44:10 | 00,633,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CertEnrollUI.dll
[2009/08/16 10:44:10 | 00,614,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ci.dll
[2009/08/16 10:44:10 | 00,597,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cscui.dll
[2009/08/16 10:44:10 | 00,507,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\bthport.sys
[2009/08/16 10:44:10 | 00,491,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cscsvc.dll
[2009/08/16 10:44:10 | 00,478,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DevicePairing.dll
[2009/08/16 10:44:10 | 00,351,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\csc.sys
[2009/08/16 10:44:10 | 00,323,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certcli.dll
[2009/08/16 10:44:10 | 00,245,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\clfs.sys
[2009/08/16 10:44:10 | 00,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cscript.exe
[2009/08/16 10:44:10 | 00,131,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cscobj.dll
[2009/08/16 10:44:10 | 00,129,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cryptsvc.dll
[2009/08/16 10:44:10 | 00,125,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Classpnp.sys
[2009/08/16 10:44:10 | 00,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cintlgnt.ime
[2009/08/16 10:44:10 | 00,106,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CscMig.dll
[2009/08/16 10:44:10 | 00,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\cdrom.sys
[2009/08/16 10:44:10 | 00,065,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DevicePairingWizard.exe
[2009/08/16 10:44:10 | 00,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\davclnt.dll
[2009/08/16 10:44:10 | 00,058,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cipher.exe
[2009/08/16 10:44:10 | 00,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DevicePairingProxy.dll
[2009/08/16 10:44:10 | 00,046,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrstub.exe
[2009/08/16 10:44:10 | 00,045,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dataclen.dll
[2009/08/16 10:44:10 | 00,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cbsra.exe
[2009/08/16 10:44:10 | 00,040,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bthserv.dll
[2009/08/16 10:44:10 | 00,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2009/08/16 10:44:10 | 00,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bthudtask.exe
[2009/08/16 10:44:10 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cscapi.dll
[2009/08/16 10:44:10 | 00,029,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\BTHUSB.SYS
[2009/08/16 10:44:10 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DeviceEject.exe
[2009/08/16 10:44:10 | 00,022,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cscdll.dll
[2009/08/16 10:44:10 | 00,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CHxReadingStringIME.dll
[2009/08/16 10:44:09 | 02,241,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msi.dll
[2009/08/16 10:44:09 | 01,053,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtctm.dll
[2009/08/16 10:44:09 | 00,799,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certutil.exe
[2009/08/16 10:44:09 | 00,564,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msftedit.dll
[2009/08/16 10:44:09 | 00,409,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msexch40.dll
[2009/08/16 10:44:09 | 00,339,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msexcl40.dll
[2009/08/16 10:44:09 | 00,332,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msihnd.dll
[2009/08/16 10:44:09 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certreq.exe
[2009/08/16 10:44:09 | 00,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\chajei.ime
[2009/08/16 10:44:09 | 00,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msiexec.exe
[2009/08/16 10:44:09 | 00,040,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certprop.dll
[2009/08/16 10:44:09 | 00,022,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\chgport.exe
[2009/08/16 10:44:09 | 00,020,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\chgusr.exe
[2009/08/16 10:44:09 | 00,020,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\chglogon.exe
[2009/08/16 10:44:09 | 00,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\change.exe
[2009/08/16 10:44:09 | 00,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdxm.ocx
[2009/08/16 10:44:08 | 02,225,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netcenter.dll
[2009/08/16 10:44:08 | 01,102,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmsys.cpl
[2009/08/16 10:44:08 | 01,086,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NetProjW.dll
[2009/08/16 10:44:08 | 00,807,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msctf.dll
[2009/08/16 10:44:08 | 00,592,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netlogon.dll
[2009/08/16 10:44:08 | 00,560,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtcprx.dll
[2009/08/16 10:44:08 | 00,527,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ndis.sys
[2009/08/16 10:44:08 | 00,467,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netapi32.dll
[2009/08/16 10:44:08 | 00,445,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncryptui.dll
[2009/08/16 10:44:08 | 00,407,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MPSSVC.dll
[2009/08/16 10:44:08 | 00,391,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscms.dll
[2009/08/16 10:44:08 | 00,332,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdrm.dll
[2009/08/16 10:44:08 | 00,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\modemui.dll
[2009/08/16 10:44:08 | 00,278,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscoree.dll
[2009/08/16 10:44:08 | 00,223,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\netio.sys
[2009/08/16 10:44:08 | 00,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscandui.dll
[2009/08/16 10:44:08 | 00,212,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb10.sys
[2009/08/16 10:44:08 | 00,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncrypt.dll
[2009/08/16 10:44:08 | 00,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\netbt.sys
[2009/08/16 10:44:08 | 00,180,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netplwiz.dll
[2009/08/16 10:44:08 | 00,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2009/08/16 10:44:08 | 00,155,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscorier.dll
[2009/08/16 10:44:08 | 00,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MMDevAPI.dll
[2009/08/16 10:44:08 | 00,121,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ndiswan.sys
[2009/08/16 10:44:08 | 00,114,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxdav.sys
[2009/08/16 10:44:08 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb.sys
[2009/08/16 10:44:08 | 00,097,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mprapi.dll
[2009/08/16 10:44:08 | 00,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msctfui.dll
[2009/08/16 10:44:08 | 00,084,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msctfp.dll
[2009/08/16 10:44:08 | 00,080,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscories.dll
[2009/08/16 10:44:08 | 00,079,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb20.sys
[2009/08/16 10:44:08 | 00,068,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpr.dll
[2009/08/16 10:44:08 | 00,027,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\msahci.sys
[2009/08/16 10:44:08 | 00,021,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msacm32.drv
[2009/08/16 10:44:08 | 00,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MsCtfMonitor.dll
[2009/08/16 10:44:08 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msimsg.dll
[2009/08/16 10:44:07 | 03,174,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netshell.dll
[2009/08/16 10:44:07 | 03,072,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\networkmap.dll
[2009/08/16 10:44:07 | 02,226,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\networkexplorer.dll
[2009/08/16 10:44:07 | 02,066,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstscax.dll
[2009/08/16 10:44:07 | 01,589,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msjet40.dll
[2009/08/16 10:44:07 | 01,336,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxml6.dll
[2009/08/16 10:44:07 | 01,183,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxml3.dll
[2009/08/16 10:44:07 | 00,856,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mswdat10.dll
[2009/08/16 10:44:07 | 00,805,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NaturalLanguage6.dll
[2009/08/16 10:44:07 | 00,643,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrepl40.dll
[2009/08/16 10:44:07 | 00,618,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mswstr10.dll
[2009/08/16 10:44:07 | 00,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSMPEG2VDEC.DLL
[2009/08/16 10:44:07 | 00,469,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\newdev.dll
[2009/08/16 10:44:07 | 00,454,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msxbde40.dll
[2009/08/16 10:44:07 | 00,408,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msinfo32.exe
[2009/08/16 10:44:07 | 00,406,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msvcp60.dll
[2009/08/16 10:44:07 | 00,368,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mspbde40.dll
[2009/08/16 10:44:07 | 00,344,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrd3x40.dll
[2009/08/16 10:44:07 | 00,319,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrd2x40.dll
[2009/08/16 10:44:07 | 00,310,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mtxclu.dll
[2009/08/16 10:44:07 | 00,290,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msjtes40.dll
[2009/08/16 10:44:07 | 00,241,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msltus40.dll
[2009/08/16 10:44:07 | 00,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mswsock.dll
[2009/08/16 10:44:07 | 00,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msv1_0.dll
[2009/08/16 10:44:07 | 00,180,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\msiscsi.sys
[2009/08/16 10:44:07 | 00,179,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msnetobj.dll
[2009/08/16 10:44:07 | 00,163,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msutb.dll
[2009/08/16 10:44:07 | 00,161,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\msrpc.sys
[2009/08/16 10:44:07 | 00,104,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netiohlp.dll
[2009/08/16 10:44:07 | 00,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSNP.ax
[2009/08/16 10:44:07 | 00,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\newdev.exe
[2009/08/16 10:44:07 | 00,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msjter40.dll
[2009/08/16 10:44:07 | 00,060,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscntrs.dll
[2009/08/16 10:44:07 | 00,048,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mup.sys
[2009/08/16 10:44:07 | 00,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\networkitemfactory.dll
[2009/08/16 10:44:07 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscb.dll
[2009/08/16 10:44:07 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msimtf.dll
[2009/08/16 10:44:07 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msjint40.dll
[2009/08/16 10:44:07 | 00,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NcdProp.dll
[2009/08/16 10:44:07 | 00,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msisip.dll
[2009/08/16 10:44:06 | 01,544,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSVidCtl.dll
[2009/08/16 10:44:06 | 01,480,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssrch.dll
[2009/08/16 10:44:06 | 00,738,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcomm.dll
[2009/08/16 10:44:06 | 00,679,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msvcrt.dll
[2009/08/16 10:44:06 | 00,678,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstsc.exe
[2009/08/16 10:44:06 | 00,670,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssvp.dll
[2009/08/16 10:44:06 | 00,414,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscp.dll
[2009/08/16 10:44:06 | 00,413,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imkr80.ime
[2009/08/16 10:44:06 | 00,351,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssph.dll
[2009/08/16 10:44:06 | 00,282,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstext40.dll
[2009/08/16 10:44:06 | 00,231,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshsq.dll
[2009/08/16 10:44:06 | 00,217,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\InkEd.dll
[2009/08/16 10:44:06 | 00,203,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssphtb.dll
[2009/08/16 10:44:06 | 00,122,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetpp.dll
[2009/08/16 10:44:06 | 00,099,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardapi.dll
[2009/08/16 10:44:06 | 00,087,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssitlb.dll
[2009/08/16 10:44:06 | 00,084,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstlsapi.dll
[2009/08/16 10:44:06 | 00,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msstrc.dll
[2009/08/16 10:44:06 | 00,035,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardcpl.cpl
[2009/08/16 10:44:06 | 00,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssprxy.dll
[2009/08/16 10:44:06 | 00,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetppui.dll
[2009/08/16 10:44:06 | 00,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshooks.dll
[2009/08/16 10:44:05 | 00,759,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ipsecsnp.dll
[2009/08/16 10:44:05 | 00,619,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardagt.exe
[2009/08/16 10:44:05 | 00,396,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ipsmsnap.dll
[2009/08/16 10:44:05 | 00,364,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IPSECSVC.DLL
[2009/08/16 10:44:05 | 00,252,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iassdo.dll
[2009/08/16 10:44:05 | 00,200,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\input.dll
[2009/08/16 10:44:05 | 00,199,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iphlpsvc.dll
[2009/08/16 10:44:05 | 00,182,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iassam.dll
[2009/08/16 10:44:05 | 00,158,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasrad.dll
[2009/08/16 10:44:05 | 00,119,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasrecst.dll
[2009/08/16 10:44:05 | 00,114,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imm32.dll
[2009/08/16 10:44:05 | 00,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IPHLPAPI.DLL
[2009/08/16 10:44:05 | 00,076,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iassvcs.dll
[2009/08/16 10:44:05 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iaspolcy.dll
[2009/08/16 10:44:05 | 00,029,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ifmon.dll
[2009/08/16 10:44:05 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ipconfig.exe
[2009/08/16 10:44:05 | 00,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iscsilog.dll
[2009/08/16 10:44:05 | 00,009,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardres.dll
[2009/08/16 10:44:04 | 02,868,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2009/08/16 10:44:04 | 02,012,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\milcore.dll
[2009/08/16 10:44:04 | 01,160,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42u.dll
[2009/08/16 10:44:04 | 01,135,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42.dll
[2009/08/16 10:44:04 | 00,883,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IMJP10.IME
[2009/08/16 10:44:04 | 00,729,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IMJP10K.DLL
[2009/08/16 10:44:04 | 00,677,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imapi2fs.dll
[2009/08/16 10:44:04 | 00,438,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IKEEXT.DLL
[2009/08/16 10:44:04 | 00,378,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imapi2.dll
[2009/08/16 10:44:04 | 00,208,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfplat.dll
[2009/08/16 10:44:04 | 00,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imapi.dll
[2009/08/16 10:44:04 | 00,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfps.dll
[2009/08/16 10:44:04 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfpmp.exe
[2009/08/16 10:44:04 | 00,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mferror.dll
[2009/08/16 10:44:03 | 11,967,524 | —- | C] () – C:\Windows\System32\korwbrkr.lex
[2009/08/16 10:44:03 | 02,167,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmcndmgr.dll
[2009/08/16 10:44:03 | 01,792,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmc.exe
[2009/08/16 10:44:03 | 00,497,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kerberos.dll
[2009/08/16 10:44:03 | 00,439,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ksecdd.sys
[2009/08/16 10:44:03 | 00,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ks.sys
[2009/08/16 10:44:03 | 00,143,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\korwbrkr.dll
[2009/08/16 10:44:03 | 00,093,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Kswdmcap.ax
[2009/08/16 10:44:03 | 00,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmci.dll
[2009/08/16 10:44:03 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\l2nacp.dll
[2009/08/16 10:44:03 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mimefilt.dll
[2009/08/16 10:44:03 | 00,017,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kd1394.dll
[2009/08/16 10:44:03 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\midimap.dll
[2009/08/16 10:44:03 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\kbdhid.sys
[2009/08/16 10:44:03 | 00,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmcico.dll
[2009/08/16 10:44:02 | 03,662,128 | —- | C] () – C:\Windows\System32\locale.nls
[2009/08/16 10:44:02 | 02,034,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2009/08/16 10:44:02 | 01,257,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lsasrv.dll
[2009/08/16 10:44:02 | 01,143,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wercon.exe
[2009/08/16 10:44:02 | 01,020,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wdc.dll
[2009/08/16 10:44:02 | 01,017,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtsvc.dll
[2009/08/16 10:44:02 | 00,950,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mblctr.exe
[2009/08/16 10:44:02 | 00,891,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsUltimateExtrasCPL.dll
[2009/08/16 10:44:02 | 00,891,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kernel32.dll
[2009/08/16 10:44:02 | 00,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wer.dll
[2009/08/16 10:44:02 | 00,860,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WerFaultSecure.exe
[2009/08/16 10:44:02 | 00,852,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mcmde.dll
[2009/08/16 10:44:02 | 00,840,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WFS.exe
[2009/08/16 10:44:02 | 00,712,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecs.dll
[2009/08/16 10:44:02 | 00,710,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Magnify.exe
[2009/08/16 10:44:02 | 00,638,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Utilman.exe
[2009/08/16 10:44:02 | 00,627,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\user32.dll
[2009/08/16 10:44:02 | 00,621,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\localspl.dll
[2009/08/16 10:44:02 | 00,547,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wiaaut.dll
[2009/08/16 10:44:02 | 00,507,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vdsdyn.dll
[2009/08/16 10:44:02 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wiaservc.dll
[2009/08/16 10:44:02 | 00,443,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32spl.dll
[2009/08/16 10:44:02 | 00,438,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mcupdate_GenuineIntel.dll
[2009/08/16 10:44:02 | 00,385,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vds.exe
[2009/08/16 10:44:02 | 00,375,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winhttp.dll
[2009/08/16 10:44:02 | 00,356,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MediaMetadataHandler.dll
[2009/08/16 10:44:02 | 00,347,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2009/08/16 10:44:02 | 00,250,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtapi.dll
[2009/08/16 10:44:02 | 00,226,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbport.sys
[2009/08/16 10:44:02 | 00,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wdscore.dll
[2009/08/16 10:44:02 | 00,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WerFault.exe
[2009/08/16 10:44:02 | 00,208,966 | —- | C] () – C:\Windows\System32\WFP.TMF
[2009/08/16 10:44:02 | 00,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WebClnt.dll
[2009/08/16 10:44:02 | 00,167,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wdmaud.drv
[2009/08/16 10:44:02 | 00,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtutil.exe
[2009/08/16 10:44:02 | 00,128,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vdsutil.dll
[2009/08/16 10:44:02 | 00,126,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wersvc.dll
[2009/08/16 10:44:02 | 00,101,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shsetup.dll
[2009/08/16 10:44:02 | 00,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\logagent.exe
[2009/08/16 10:44:02 | 00,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\logman.exe
[2009/08/16 10:44:02 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\whealogr.dll
[2009/08/16 10:44:02 | 00,029,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\uxsms.dll
[2009/08/16 10:44:02 | 00,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\version.dll
[2009/08/16 10:44:02 | 00,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\logoff.exe
[2009/08/16 10:44:02 | 00,019,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kdusb.dll
[2009/08/16 10:44:02 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vdmdbg.dll
[2009/08/16 10:44:02 | 00,017,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kdcom.dll
[2009/08/16 10:44:01 | 03,217,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinSAT.exe
[2009/08/16 10:44:01 | 02,499,629 | —- | C] () – C:\Windows\System32\wlan.tmf
[2009/08/16 10:44:01 | 02,386,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVCORE.DLL
[2009/08/16 10:44:01 | 01,695,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuaueng.dll
[2009/08/16 10:44:01 | 01,689,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscui.cpl
[2009/08/16 10:44:01 | 01,671,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanpref.dll
[2009/08/16 10:44:01 | 01,580,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpccpl.dll
[2009/08/16 10:44:01 | 01,575,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVENCOD.DLL
[2009/08/16 10:44:01 | 01,533,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wcnwiz.dll
[2009/08/16 10:44:01 | 01,505,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wucltux.dll
[2009/08/16 10:44:01 | 01,382,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVSDECD.DLL
[2009/08/16 10:44:01 | 01,123,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\usercpl.dll
[2009/08/16 10:44:01 | 01,077,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vssapi.dll
[2009/08/16 10:44:01 | 01,055,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\VSSVC.exe
[2009/08/16 10:44:01 | 00,996,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMNetMgr.dll
[2009/08/16 10:44:01 | 00,986,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winload.exe
[2009/08/16 10:44:01 | 00,968,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wcnwiz2.dll
[2009/08/16 10:44:01 | 00,926,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winresume.exe
[2009/08/16 10:44:01 | 00,918,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wbengine.exe
[2009/08/16 10:44:01 | 00,867,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpmde.dll
[2009/08/16 10:44:01 | 00,747,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmSvc.dll
[2009/08/16 10:44:01 | 00,657,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVXENCD.DLL
[2009/08/16 10:44:01 | 00,532,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpcao.dll
[2009/08/16 10:44:01 | 00,532,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapi.dll
[2009/08/16 10:44:01 | 00,514,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlansvc.dll
[2009/08/16 10:44:01 | 00,502,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\usp10.dll
[2009/08/16 10:44:01 | 00,413,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wcncsvc.dll
[2009/08/16 10:44:01 | 00,399,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlangpui.dll
[2009/08/16 10:44:01 | 00,375,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2009/08/16 10:44:01 | 00,355,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSDApi.dll
[2009/08/16 10:44:01 | 00,321,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2009/08/16 10:44:01 | 00,314,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winlogon.exe
[2009/08/16 10:44:01 | 00,303,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpeffects.dll
[2009/08/16 10:44:01 | 00,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanmsm.dll
[2009/08/16 10:44:01 | 00,292,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\volmgrx.sys
[2009/08/16 10:44:01 | 00,291,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WscEapPr.dll
[2009/08/16 10:44:01 | 00,287,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Wldap32.dll
[2009/08/16 10:44:01 | 00,282,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\w32time.dll
[2009/08/16 10:44:01 | 00,273,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wow32.dll
[2009/08/16 10:44:01 | 00,258,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winspool.drv
[2009/08/16 10:44:01 | 00,244,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wisptis.exe
[2009/08/16 10:44:01 | 00,226,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\volsnap.sys
[2009/08/16 10:44:01 | 00,223,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscntfy.dll
[2009/08/16 10:44:01 | 00,202,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanui.dll
[2009/08/16 10:44:01 | 00,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winmm.dll
[2009/08/16 10:44:01 | 00,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSDMon.dll
[2009/08/16 10:44:01 | 00,165,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WcnNetsh.dll
[2009/08/16 10:44:01 | 00,155,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscript.exe
[2009/08/16 10:44:01 | 00,140,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wusa.exe
[2009/08/16 10:44:01 | 00,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpcsvc.dll
[2009/08/16 10:44:01 | 00,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wshom.ocx
[2009/08/16 10:44:01 | 00,115,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinSCard.dll
[2009/08/16 10:44:01 | 00,108,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\userenv.dll
[2009/08/16 10:44:01 | 00,090,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wshext.dll
[2009/08/16 10:44:01 | 00,083,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlgpclnt.dll
[2009/08/16 10:44:01 | 00,068,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanhlp.dll
[2009/08/16 10:44:01 | 00,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscsvc.dll
[2009/08/16 10:44:01 | 00,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xmlfilter.dll
[2009/08/16 10:44:01 | 00,050,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsnmp32.dll
[2009/08/16 10:44:01 | 00,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wshbth.dll
[2009/08/16 10:44:01 | 00,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscapi.dll
[2009/08/16 10:44:01 | 00,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\watchdog.sys
[2009/08/16 10:44:01 | 00,029,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsepno.dll
[2009/08/16 10:44:01 | 00,020,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsdchngr.dll
[2009/08/16 10:44:01 | 00,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrnr.dll
[2009/08/16 10:44:01 | 00,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscisvif.dll
[2009/08/16 10:44:00 | 10,624,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmp.dll
[2009/08/16 10:44:00 | 08,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2009/08/16 10:44:00 | 02,205,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SyncCenter.dll
[2009/08/16 10:44:00 | 01,224,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sud.dll
[2009/08/16 10:44:00 | 00,777,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slcc.dll
[2009/08/16 10:44:00 | 00,705,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SmiEngine.dll
[2009/08/16 10:44:00 | 00,586,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\stobject.dll
[2009/08/16 10:44:00 | 00,558,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sysmain.dll
[2009/08/16 10:44:00 | 00,533,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmdrmsdk.dll
[2009/08/16 10:44:00 | 00,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sysmon.ocx
[2009/08/16 10:44:00 | 00,378,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srcore.dll
[2009/08/16 10:44:00 | 00,343,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmicmiplugin.dll
[2009/08/16 10:44:00 | 00,311,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\swprv.dll
[2009/08/16 10:44:00 | 00,301,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srchadmin.dll
[2009/08/16 10:44:00 | 00,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\srv.sys
[2009/08/16 10:44:00 | 00,144,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\srv2.sys
[2009/08/16 10:44:00 | 00,134,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SmartcardCredentialProvider.dll
[2009/08/16 10:44:00 | 00,122,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srvsvc.dll
[2009/08/16 10:44:00 | 00,122,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Storport.sys
[2009/08/16 10:44:00 | 00,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/08/16 10:44:00 | 00,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sysclass.dll
[2009/08/16 10:44:00 | 00,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\srvnet.sys
[2009/08/16 10:44:00 | 00,083,456 | —- | C] (Microsoft) – C:\Windows\System32\SMBHelperClass.dll
[2009/08/16 10:44:00 | 00,067,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slwmi.dll
[2009/08/16 10:44:00 | 00,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\smb.sys
[2009/08/16 10:44:00 | 00,064,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\smss.exe
[2009/08/16 10:44:00 | 00,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Storprop.dll
[2009/08/16 10:44:00 | 00,052,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\stream.sys
[2009/08/16 10:44:00 | 00,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/08/16 10:43:59 | 03,408,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLsvc.exe
[2009/08/16 10:43:59 | 01,081,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLCExt.dll
[2009/08/16 10:43:59 | 00,842,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\systemcpl.dll
[2009/08/16 10:43:59 | 00,684,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\spsys.sys
[2009/08/16 10:43:59 | 00,582,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLCommDlg.dll
[2009/08/16 10:43:59 | 00,524,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sqlsrv32.dll
[2009/08/16 10:43:59 | 00,425,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shwebsvc.dll
[2009/08/16 10:43:59 | 00,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLUI.exe
[2009/08/16 10:43:59 | 00,342,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\zipfldr.dll
[2009/08/16 10:43:59 | 00,324,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\untfs.dll
[2009/08/16 10:43:59 | 00,289,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spinstall.exe
[2009/08/16 10:43:59 | 00,280,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\unimdm.tsp
[2009/08/16 10:43:59 | 00,275,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SnippingTool.exe
[2009/08/16 10:43:59 | 00,247,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shsvcs.dll
[2009/08/16 10:43:59 | 00,228,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLC.dll
[2009/08/16 10:43:59 | 00,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\udfs.sys
[2009/08/16 10:43:59 | 00,222,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\umpnpmgr.dll
[2009/08/16 10:43:59 | 00,212,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\umrdp.dll
[2009/08/16 10:43:59 | 00,203,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\uDWM.dll
[2009/08/16 10:43:59 | 00,197,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SndVol.exe
[2009/08/16 10:43:59 | 00,196,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbhub.sys
[2009/08/16 10:43:59 | 00,190,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sperror.dll
[2009/08/16 10:43:59 | 00,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLLUA.exe
[2009/08/16 10:43:59 | 00,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwizui.dll
[2009/08/16 10:43:59 | 00,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spoolss.dll
[2009/08/16 10:43:59 | 00,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spp.dll
[2009/08/16 10:43:59 | 00,130,008 | —- | C] () – C:\Windows\System32\systemsf.ebd
[2009/08/16 10:43:59 | 00,127,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spoolsv.exe
[2009/08/16 10:43:59 | 00,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\softkbd.dll
[2009/08/16 10:43:59 | 00,112,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spreview.exe
[2009/08/16 10:43:59 | 00,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ulib.dll
[2009/08/16 10:43:59 | 00,092,918 | —- | C] () – C:\Windows\System32\slmgr.vbs
[2009/08/16 10:43:59 | 00,063,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tscupgrd.exe
[2009/08/16 10:43:59 | 00,060,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SLUINotify.dll
[2009/08/16 10:43:59 | 00,053,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tsgqec.dll
[2009/08/16 10:43:59 | 00,042,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slcinst.dll
[2009/08/16 10:43:59 | 00,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbehci.sys
[2009/08/16 10:43:59 | 00,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TSTheme.exe
[2009/08/16 10:43:59 | 00,035,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TsWpfWrp.exe
[2009/08/16 10:43:59 | 00,025,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\USBCAMD2.sys
[2009/08/16 10:43:59 | 00,025,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\USBCAMD.sys
[2009/08/16 10:43:59 | 00,022,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tskill.exe
[2009/08/16 10:43:59 | 00,020,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tsdiscon.exe
[2009/08/16 10:43:59 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usb8023.sys
[2009/08/16 10:43:59 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spcmsg.dll
[2009/08/16 10:43:59 | 00,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\slwga.dll
[2009/08/16 10:43:59 | 00,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwinsat.dll
[2009/08/16 10:43:59 | 00,009,239 | —- | C] () – C:\Windows\System32\spcinstrumentation.man
[2009/08/16 10:43:59 | 00,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwmp.dll
[2009/08/16 10:43:58 | 01,576,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tquery.dll
[2009/08/16 10:43:58 | 01,152,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\themecpl.dll
[2009/08/16 10:43:58 | 00,897,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\tcpip.sys
[2009/08/16 10:43:58 | 00,714,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\timedate.cpl
[2009/08/16 10:43:58 | 00,615,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\themeui.dll
[2009/08/16 10:43:58 | 00,449,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\termsrv.dll
[2009/08/16 10:43:58 | 00,313,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\thawbrkr.dll
[2009/08/16 10:43:58 | 00,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskcomp.dll
[2009/08/16 10:43:58 | 00,242,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tapisrv.dll
[2009/08/16 10:43:58 | 00,170,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tcpipcfg.dll
[2009/08/16 10:43:58 | 00,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskeng.exe
[2009/08/16 10:43:58 | 00,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tscfgwmi.dll
[2009/08/16 10:43:58 | 00,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tcpmon.dll
[2009/08/16 10:43:58 | 00,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tintlgnt.ime
[2009/08/16 10:43:58 | 00,072,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\tdx.sys
[2009/08/16 10:43:58 | 00,053,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\termdd.sys
[2009/08/16 10:43:58 | 00,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\tcpipreg.sys
[2009/08/16 10:43:58 | 00,021,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tscon.exe
[2009/08/16 10:43:58 | 00,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tsbyuv.dll
[2009/08/16 10:41:28 | 00,000,000 | —D | C] – C:\Windows\System32\EventProviders
[2009/08/16 10:25:38 | 00,000,000 | —D | C] – C:\Windows\Panther
[2009/08/16 10:06:15 | 00,193,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\recdisc.exe
[2009/08/16 10:06:13 | 00,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdspres.dll
[2009/08/16 10:06:03 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sxproxy.dll
[2009/08/16 10:05:43 | 00,464,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msra.exe
[2009/08/16 10:05:43 | 00,221,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Mystify.scr
[2009/08/16 10:05:43 | 00,206,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstask.dll
[2009/08/16 10:05:43 | 00,169,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssha.dll
[2009/08/16 10:05:43 | 00,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrdc.dll
[2009/08/16 10:05:43 | 00,153,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NAPMONTR.DLL
[2009/08/16 10:05:43 | 00,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mydocs.dll
[2009/08/16 10:05:43 | 00,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mtstocom.exe
[2009/08/16 10:05:43 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscript.ocx
[2009/08/16 10:05:43 | 00,105,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mtxoci.dll
[2009/08/16 10:05:43 | 00,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NAPHLPR.DLL
[2009/08/16 10:05:43 | 00,067,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\napdsnap.dll
[2009/08/16 10:05:43 | 00,066,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MuiUnattend.exe
[2009/08/16 10:05:43 | 00,050,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NapiNSP.dll
[2009/08/16 10:05:43 | 00,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\napipsec.dll
[2009/08/16 10:05:43 | 00,031,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mssmbios.sys
[2009/08/16 10:05:43 | 00,027,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mtxlegih.dll
[2009/08/16 10:05:43 | 00,022,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mtxdm.dll
[2009/08/16 10:05:43 | 00,006,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mstee.sys
[2009/08/16 10:05:43 | 00,005,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mspclock.sys
[2009/08/16 10:05:43 | 00,005,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mspqm.sys
[2009/08/16 10:05:42 | 01,386,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msvbvm60.dll
[2009/08/16 10:05:42 | 00,312,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mswmdm.dll
[2009/08/16 10:05:42 | 00,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mycomput.dll
[2009/08/16 10:05:42 | 00,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtcuiu.dll
[2009/08/16 10:05:42 | 00,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msvfw32.dll
[2009/08/16 10:05:42 | 00,046,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NAPCRYPT.DLL
[2009/08/16 10:05:42 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msvidc32.dll
[2009/08/16 10:05:42 | 00,022,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\msfs.sys
[2009/08/16 10:05:42 | 00,020,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtcVSp1res.dll
[2009/08/16 10:05:41 | 00,506,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSMPEG2ENC.DLL
[2009/08/16 10:05:41 | 00,485,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mspaint.exe
[2009/08/16 10:05:41 | 00,415,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdri.dll
[2009/08/16 10:05:41 | 00,391,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSMPEG2ADEC.DLL
[2009/08/16 10:05:41 | 00,344,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtckrm.dll
[2009/08/16 10:05:41 | 00,305,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdelta.dll
[2009/08/16 10:05:41 | 00,212,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdt.dll
[2009/08/16 10:05:41 | 00,205,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msoeacct.dll
[2009/08/16 10:05:41 | 00,180,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msorcl32.dll
[2009/08/16 10:05:41 | 00,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdt.exe
[2009/08/16 10:05:41 | 00,159,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdadiag.dll
[2009/08/16 10:05:41 | 00,126,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdart.dll
[2009/08/16 10:05:41 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtc.exe
[2009/08/16 10:05:41 | 00,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtclog.dll
[2009/08/16 10:05:41 | 00,087,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msoert2.dll
[2009/08/16 10:05:41 | 00,058,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msobjs.dll
[2009/08/16 10:05:41 | 00,053,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msident.dll
[2009/08/16 10:05:41 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mspatcha.dll
[2009/08/16 10:05:41 | 00,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdmo.dll
[2009/08/16 10:05:41 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msg.exe
[2009/08/16 10:05:41 | 00,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msmmsp.dll
[2009/08/16 10:05:41 | 00,008,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msidle.dll
[2009/08/16 10:05:41 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mskssrv.sys
[2009/08/16 10:05:41 | 00,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01007_Inbox_Critical.Wdf
[2009/08/16 10:05:40 | 03,104,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData004b.dll
[2009/08/16 10:05:40 | 03,104,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData004a.dll
[2009/08/16 10:05:40 | 03,104,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0049.dll
[2009/08/16 10:05:40 | 03,104,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0047.dll
[2009/08/16 10:05:40 | 03,104,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0046.dll
[2009/08/16 10:05:40 | 03,104,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0045.dll
[2009/08/16 10:05:40 | 01,965,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0024.dll
[2009/08/16 10:05:40 | 01,801,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData003e.dll
[2009/08/16 10:05:40 | 00,475,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msidcrl30.dll
[2009/08/16 10:05:40 | 00,296,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msieftp.dll
[2009/08/16 10:05:40 | 00,016,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\msisadrv.sys
[2009/08/16 10:05:39 | 09,847,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData000a.dll
[2009/08/16 10:05:39 | 04,875,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0009.dll
[2009/08/16 10:05:39 | 04,497,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0019.dll
[2009/08/16 10:05:39 | 04,495,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0816.dll
[2009/08/16 10:05:39 | 04,495,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0416.dll
[2009/08/16 10:05:39 | 04,495,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0414.dll
[2009/08/16 10:05:39 | 03,104,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData004e.dll
[2009/08/16 10:05:39 | 03,104,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData004c.dll
[2009/08/16 10:05:39 | 03,104,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0039.dll
[2009/08/16 10:05:39 | 03,104,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0020.dll
[2009/08/16 10:05:39 | 02,599,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0001.dll
[2009/08/16 10:05:39 | 02,243,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0007.dll
[2009/08/16 10:05:39 | 01,966,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0027.dll
[2009/08/16 10:05:39 | 01,965,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0c1a.dll
[2009/08/16 10:05:39 | 01,965,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData081a.dll
[2009/08/16 10:05:39 | 01,965,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0026.dll
[2009/08/16 10:05:39 | 01,965,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData001b.dll
[2009/08/16 10:05:39 | 01,965,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData001a.dll
[2009/08/16 10:05:39 | 01,965,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0018.dll
[2009/08/16 10:05:39 | 01,965,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0003.dll
[2009/08/16 10:05:39 | 01,965,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0002.dll
[2009/08/16 10:05:39 | 01,801,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData002a.dll
[2009/08/16 10:05:39 | 01,801,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0022.dll
[2009/08/16 10:05:39 | 01,801,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0021.dll
[2009/08/16 10:05:39 | 01,523,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0000.dll
[2009/08/16 10:05:39 | 00,154,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nlmgp.dll
[2009/08/16 10:05:39 | 00,151,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\notepad.exe
[2009/08/16 10:05:39 | 00,151,040 | —- | C] (Microsoft Corporation) – C:\Windows\notepad.exe
[2009/08/16 10:05:39 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nlsbres.dll
[2009/08/16 10:05:39 | 00,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Nlsdl.dll
[2009/08/16 10:05:38 | 04,495,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData001d.dll
[2009/08/16 10:05:38 | 04,495,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0010.dll
[2009/08/16 10:05:38 | 03,466,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0013.dll
[2009/08/16 10:05:38 | 02,657,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData0011.dll
[2009/08/16 10:05:38 | 02,643,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData000c.dll
[2009/08/16 10:05:38 | 02,342,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData000d.dll
[2009/08/16 10:05:38 | 01,965,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NlsData000f.dll
[2009/08/16 10:05:38 | 00,531,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\objsel.dll
[2009/08/16 10:05:38 | 00,520,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntvdm.exe
[2009/08/16 10:05:38 | 00,352,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nshipsec.dll
[2009/08/16 10:05:38 | 00,319,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbcjt32.dll
[2009/08/16 10:05:38 | 00,296,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntshrui.dll
[2009/08/16 10:05:38 | 00,159,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbctrac.dll
[2009/08/16 10:05:38 | 00,088,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntdsapi.dll
[2009/08/16 10:05:38 | 00,077,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbccu32.dll
[2009/08/16 10:05:38 | 00,077,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbccr32.dll
[2009/08/16 10:05:38 | 00,063,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntlanman.dll
[2009/08/16 10:05:38 | 00,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\odbcbcp.dll
[2009/08/16 10:05:38 | 00,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nshhttp.dll
[2009/08/16 10:05:38 | 00,018,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nsisvc.dll
[2009/08/16 10:05:38 | 00,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\nsiproxy.sys
[2009/08/16 10:05:38 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nsi.dll
[2009/08/16 10:05:38 | 00,004,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\null.sys
[2009/08/16 10:05:37 | 00,669,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netprof.dll
[2009/08/16 10:05:37 | 00,386,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netcfgx.dll
[2009/08/16 10:05:37 | 00,274,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netman.dll
[2009/08/16 10:05:37 | 00,267,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NAPSTAT.EXE
[2009/08/16 10:05:37 | 00,168,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nlasvc.dll
[2009/08/16 10:05:37 | 00,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\net1.exe
[2009/08/16 10:05:37 | 00,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ndfapi.dll
[2009/08/16 10:05:37 | 00,119,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netid.dll
[2009/08/16 10:05:37 | 00,112,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netdiagfx.dll
[2009/08/16 10:05:37 | 00,112,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netcorehc.dll
[2009/08/16 10:05:37 | 00,093,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncsi.dll
[2009/08/16 10:05:37 | 00,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nci.dll
[2009/08/16 10:05:37 | 00,049,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ndproxy.sys
[2009/08/16 10:05:37 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nlaapi.dll
[2009/08/16 10:05:37 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\net.exe
[2009/08/16 10:05:37 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ncobjapi.dll
[2009/08/16 10:05:37 | 00,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\netbios.sys
[2009/08/16 10:05:37 | 00,029,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ndfetw.dll
[2009/08/16 10:05:37 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Netplwiz.exe
[2009/08/16 10:05:37 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netcfg.exe
[2009/08/16 10:05:37 | 00,022,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netiougc.exe
[2009/08/16 10:05:37 | 00,021,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netbtugc.exe
[2009/08/16 10:05:37 | 00,020,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ndistapi.sys
[2009/08/16 10:05:37 | 00,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2009/08/16 10:05:37 | 00,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ndisuio.sys
[2009/08/16 10:05:37 | 00,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\nbtstat.exe
[2009/08/16 10:05:36 | 05,714,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\logon.scr
[2009/08/16 10:05:36 | 00,614,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MFWMAAEC.DLL
[2009/08/16 10:05:36 | 00,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\localsec.dll
[2009/08/16 10:05:36 | 00,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netprofm.dll
[2009/08/16 10:05:36 | 00,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lsm.exe
[2009/08/16 10:05:36 | 00,179,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lpksetup.exe
[2009/08/16 10:05:36 | 00,128,482 | —- | C] () – C:\Windows\System32\manage-bde.wsf
[2009/08/16 10:05:36 | 00,101,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\luainstall.dll
[2009/08/16 10:05:36 | 00,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\makecab.exe
[2009/08/16 10:05:36 | 00,084,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\luafv.sys
[2009/08/16 10:05:36 | 00,081,158 | —- | C] () – C:\Windows\System32\manage-bde.ini.en
[2009/08/16 10:05:36 | 00,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\loghours.dll
[2009/08/16 10:05:36 | 00,062,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfvdsp.dll
[2009/08/16 10:05:36 | 00,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lpremove.exe
[2009/08/16 10:05:36 | 00,040,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lodctr.exe
[2009/08/16 10:05:36 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfcsubs.dll
[2009/08/16 10:05:36 | 00,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lpk.dll
[2009/08/16 10:05:36 | 00,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lsmproxy.dll
[2009/08/16 10:05:36 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\localui.dll
[2009/08/16 10:05:36 | 00,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lsass.exe
[2009/08/16 10:05:36 | 00,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\LogonUI.exe
[2009/08/16 10:05:35 | 00,337,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\intl.cpl
[2009/08/16 10:05:35 | 00,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ipnathlp.dll
[2009/08/16 10:05:35 | 00,275,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mcbuilder.exe
[2009/08/16 10:05:35 | 00,252,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iprtrmgr.dll
[2009/08/16 10:05:35 | 00,205,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mdminst.dll
[2009/08/16 10:05:35 | 00,188,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lltdsvc.dll
[2009/08/16 10:05:35 | 00,157,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\keymgr.dll
[2009/08/16 10:05:35 | 00,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ksproxy.ax
[2009/08/16 10:05:35 | 00,141,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\itss.dll
[2009/08/16 10:05:35 | 00,129,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\McxDriv.dll
[2009/08/16 10:05:35 | 00,128,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MdSched.exe
[2009/08/16 10:05:35 | 00,126,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\L2SecHC.dll
[2009/08/16 10:05:35 | 00,113,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\loadperf.dll
[2009/08/16 10:05:35 | 00,111,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iscsiexe.dll
[2009/08/16 10:05:35 | 00,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ipnat.sys
[2009/08/16 10:05:35 | 00,095,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\irda.sys
[2009/08/16 10:05:35 | 00,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IPBusEnum.dll
[2009/08/16 10:05:35 | 00,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kstvtune.ax
[2009/08/16 10:05:35 | 00,068,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KMSVC.DLL
[2009/08/16 10:05:35 | 00,064,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iscsiwmi.dll
[2009/08/16 10:05:35 | 00,053,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Mcx2Svc.dll
[2009/08/16 10:05:35 | 00,053,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\l2gpstore.dll
[2009/08/16 10:05:35 | 00,047,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ipfltdrv.sys
[2009/08/16 10:05:35 | 00,047,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\lltdio.sys
[2009/08/16 10:05:35 | 00,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ksxbar.ax
[2009/08/16 10:05:35 | 00,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\intelppm.sys
[2009/08/16 10:05:35 | 00,040,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lnkstub.exe
[2009/08/16 10:05:35 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lltdapi.dll
[2009/08/16 10:05:35 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iscsium.dll
[2009/08/16 10:05:35 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mcd.sys
[2009/08/16 10:05:35 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ktmutil.exe
[2009/08/16 10:05:35 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\irenum.sys
[2009/08/16 10:05:35 | 00,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ktmw32.dll
[2009/08/16 10:05:35 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iscsied.dll
[2009/08/16 10:05:35 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iprtprio.dll
[2009/08/16 10:05:34 | 00,442,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\joy.cpl
[2009/08/16 10:05:34 | 00,220,672 | —- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) – C:\Windows\System32\l3codecp.acm
[2009/08/16 10:05:34 | 00,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mprmsg.dll
[2009/08/16 10:05:34 | 00,104,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mprddm.dll
[2009/08/16 10:05:34 | 00,068,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mprdim.dll
[2009/08/16 10:05:34 | 00,064,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mpsdrv.sys
[2009/08/16 10:05:34 | 00,062,464 | —- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) – C:\Windows\System32\l3codeca.acm
[2009/08/16 10:05:34 | 00,057,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mountmgr.sys
[2009/08/16 10:05:34 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\monitor.sys
[2009/08/16 10:05:34 | 00,035,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\kbdclass.sys
[2009/08/16 10:05:34 | 00,034,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mouclass.sys
[2009/08/16 10:05:34 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\LangCleanupSysprepAction.dll
[2009/08/16 10:05:34 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\mouhid.sys
[2009/08/16 10:05:34 | 00,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDJPN.DLL
[2009/08/16 10:05:34 | 00,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\KBDKOR.DLL
[2009/08/16 10:05:33 | 00,317,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MP4SDECD.DLL
[2009/08/16 10:05:33 | 00,259,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MPG4DECD.DLL
[2009/08/16 10:05:33 | 00,259,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MP43DECD.DLL
[2009/08/16 10:05:33 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msconfig.exe
[2009/08/16 10:05:33 | 00,084,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MP3DMOD.DLL
[2009/08/16 10:05:33 | 00,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Mpeg2Data.ax
[2009/08/16 10:05:33 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mountvol.exe
[2009/08/16 10:05:32 | 00,301,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmcbase.dll
[2009/08/16 10:05:32 | 00,187,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mlang.dll
[2009/08/16 10:05:32 | 00,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSAC3ENC.DLL
[2009/08/16 10:05:32 | 00,127,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmcshext.dll
[2009/08/16 10:05:32 | 00,120,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msaatext.dll
[2009/08/16 10:05:32 | 00,095,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mobsync.exe
[2009/08/16 10:05:32 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msacm32.dll
[2009/08/16 10:05:32 | 00,045,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mmcss.dll
[2009/08/16 10:05:32 | 00,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\modem.sys
[2009/08/16 10:05:29 | 00,095,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\migisol.dll
[2009/08/16 10:05:29 | 00,094,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MigAutoPlay.exe
[2009/08/16 10:05:27 | 00,104,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdrsvc.dll
[2009/08/16 10:05:27 | 00,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdshext.dll
[2009/08/16 10:05:27 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SecEdit.exe
[2009/08/16 10:05:27 | 00,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\seclogon.dll
[2009/08/16 10:05:26 | 00,120,458 | —- | C] () – C:\Windows\System32\secpol.msc
[2009/08/16 10:05:25 | 00,396,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shrpubw.exe
[2009/08/16 10:05:25 | 00,128,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shimgvw.dll
[2009/08/16 10:05:25 | 00,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shrink.dll
[2009/08/16 10:05:25 | 00,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shacct.dll
[2009/08/16 10:05:25 | 00,068,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shgina.dll
[2009/08/16 10:05:25 | 00,029,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\shutdown.exe
[2009/08/16 10:05:24 | 00,139,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SmiInstaller.dll
[2009/08/16 10:05:24 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\smclib.sys
[2009/08/16 10:05:23 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\setupcln.dll
[2009/08/16 10:05:23 | 00,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\setupugc.exe
[2009/08/16 10:05:23 | 00,084,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SessEnv.dll
[2009/08/16 10:05:23 | 00,047,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Sens.dll
[2009/08/16 10:05:23 | 00,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\setbcdlocale.dll
[2009/08/16 10:05:23 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\setupcl.exe
[2009/08/16 10:05:23 | 00,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sfc_os.dll
[2009/08/16 10:05:23 | 00,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\sermouse.sys
[2009/08/16 10:05:23 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sfc.exe
[2009/08/16 10:05:23 | 00,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\serialui.dll
[2009/08/16 10:05:23 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\setupSNK.exe
[2009/08/16 10:05:22 | 00,300,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\puiobj.dll
[2009/08/16 10:05:22 | 00,272,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\polstore.dll
[2009/08/16 10:05:22 | 00,237,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ppcsnap.dll
[2009/08/16 10:05:22 | 00,196,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceWMDRM.dll
[2009/08/16 10:05:22 | 00,191,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\provthrd.dll
[2009/08/16 10:05:22 | 00,172,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\QAGENT.DLL
[2009/08/16 10:05:22 | 00,163,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\powercfg.cpl
[2009/08/16 10:05:22 | 00,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceWiaCompat.dll
[2009/08/16 10:05:22 | 00,119,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\prntvpt.dll
[2009/08/16 10:05:22 | 00,062,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pnrpnsp.dll
[2009/08/16 10:05:22 | 00,053,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PushPrinterConnections.exe
[2009/08/16 10:05:22 | 00,053,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PNPXAssocPrx.dll
[2009/08/16 10:05:22 | 00,040,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psbase.dll
[2009/08/16 10:05:22 | 00,037,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printcom.dll
[2009/08/16 10:05:22 | 00,029,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\profprov.dll
[2009/08/16 10:05:22 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\prevhost.exe
[2009/08/16 10:05:22 | 00,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pots.dll
[2009/08/16 10:05:22 | 00,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pnpts.dll
[2009/08/16 10:05:22 | 00,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\procinst.dll
[2009/08/16 10:05:21 | 01,502,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pla.dll
[2009/08/16 10:05:21 | 01,107,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ogldrv.dll
[2009/08/16 10:05:21 | 00,403,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\p2pcollab.dll
[2009/08/16 10:05:21 | 00,318,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rstrui.exe
[2009/08/16 10:05:21 | 00,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oleacc.dll
[2009/08/16 10:05:21 | 00,202,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\P2P.dll
[2009/08/16 10:05:21 | 00,192,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\p2phost.exe
[2009/08/16 10:05:21 | 00,146,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RstrtMgr.dll
[2009/08/16 10:05:21 | 00,145,455 | —- | C] () – C:\Windows\System32\perfmon.msc
[2009/08/16 10:05:21 | 00,134,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\p2pnetsh.dll
[2009/08/16 10:05:21 | 00,120,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\perfmon.exe
[2009/08/16 10:05:21 | 00,114,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rtm.dll
[2009/08/16 10:05:21 | 00,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\oledlg.dll
[2009/08/16 10:05:21 | 00,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\OptionalFeatures.exe
[2009/08/16 10:05:21 | 00,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\olecli32.dll
[2009/08/16 10:05:21 | 00,077,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\olethk32.dll
[2009/08/16 10:05:21 | 00,060,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rspndr.sys
[2009/08/16 10:05:21 | 00,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pdhui.dll
[2009/08/16 10:05:21 | 00,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rshx32.dll
[2009/08/16 10:05:21 | 00,042,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\osblprov.dll
[2009/08/16 10:05:21 | 00,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\runonce.exe
[2009/08/16 10:05:21 | 00,037,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pcasvc.dll
[2009/08/16 10:05:21 | 00,027,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\olesvr32.dll
[2009/08/16 10:05:21 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pcadm.dll
[2009/08/16 10:05:21 | 00,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\perfnet.dll
[2009/08/16 10:05:21 | 00,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\osbaseln.dll
[2009/08/16 10:05:21 | 00,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PlaySndSrv.dll
[2009/08/16 10:05:21 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\perfts.dll
[2009/08/16 10:05:21 | 00,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PING.EXE
[2009/08/16 10:05:20 | 00,730,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdengin2.dll
[2009/08/16 10:05:20 | 00,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbe.dll
[2009/08/16 10:05:20 | 00,281,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qdv.dll
[2009/08/16 10:05:20 | 00,243,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qwave.dll
[2009/08/16 10:05:20 | 00,220,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Ribbons.scr
[2009/08/16 10:05:20 | 00,216,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RESAMPLEDMO.DLL
[2009/08/16 10:05:20 | 00,208,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qasf.dll
[2009/08/16 10:05:20 | 00,192,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qcap.dll
[2009/08/16 10:05:20 | 00,154,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\QSHVHOST.DLL
[2009/08/16 10:05:20 | 00,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbeio.dll
[2009/08/16 10:05:20 | 00,151,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\schtasks.exe
[2009/08/16 10:05:20 | 00,151,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rgb9rast.dll
[2009/08/16 10:05:20 | 00,142,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\scsiport.sys
[2009/08/16 10:05:20 | 00,134,656 | —- | C] (Microsoft Corporation) – C:\Windows\regedit.exe
[2009/08/16 10:05:20 | 00,118,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RDPENCDD.dll
[2009/08/16 10:05:20 | 00,090,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasauto.dll
[2009/08/16 10:05:20 | 00,087,552 | —- | C] (Microsoft) – C:\Windows\System32\Robocopy.exe
[2009/08/16 10:05:20 | 00,082,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdchange.exe
[2009/08/16 10:05:20 | 00,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\QSVRMGMT.DLL
[2009/08/16 10:05:20 | 00,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rascfg.dll
[2009/08/16 10:05:20 | 00,079,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\QUTIL.DLL
[2009/08/16 10:05:20 | 00,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\QCLIPROV.DLL
[2009/08/16 10:05:20 | 00,065,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\resutils.dll
[2009/08/16 10:05:20 | 00,058,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\remotepg.dll
[2009/08/16 10:05:20 | 00,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\regini.exe
[2009/08/16 10:05:20 | 00,040,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegCtrl.dll
[2009/08/16 10:05:20 | 00,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RpcPing.exe
[2009/08/16 10:05:20 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\qwavedrv.sys
[2009/08/16 10:05:20 | 00,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdrleakdiag.exe
[2009/08/16 10:05:20 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qwinsta.exe
[2009/08/16 10:05:20 | 00,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quser.exe
[2009/08/16 10:05:20 | 00,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RacAgent.exe
[2009/08/16 10:05:20 | 00,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ROUTE.EXE
[2009/08/16 10:05:20 | 00,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasctrs.dll
[2009/08/16 10:05:20 | 00,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbunattend.exe
[2009/08/16 10:05:20 | 00,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rasacd.sys
[2009/08/16 10:05:20 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\riched32.dll
[2009/08/16 10:05:20 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rootmdm.sys
[2009/08/16 10:05:20 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\RDPENCDD.sys
[2009/08/16 10:05:20 | 00,001,820 | —- | C] () – C:\Windows\System32\rasctrnm.h
[2009/08/16 10:05:19 | 01,039,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d8.dll
[2009/08/16 10:05:19 | 01,029,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2009/08/16 10:05:19 | 00,975,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RASMM.dll
[2009/08/16 10:05:19 | 00,816,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dim700.dll
[2009/08/16 10:05:19 | 00,798,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dbghelp.dll
[2009/08/16 10:05:19 | 00,671,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dfrgui.exe
[2009/08/16 10:05:19 | 00,522,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ddraw.dll
[2009/08/16 10:05:19 | 00,384,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dim.dll
[2009/08/16 10:05:19 | 00,368,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\desk.cpl
[2009/08/16 10:05:19 | 00,318,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmd.exe
[2009/08/16 10:05:19 | 00,226,816 | —- | C] (Microsoft Corp.) – C:\Windows\System32\Defrag.exe
[2009/08/16 10:05:19 | 00,208,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2009/08/16 10:05:19 | 00,188,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2009/08/16 10:05:19 | 00,178,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\clusapi.dll
[2009/08/16 10:05:19 | 00,163,840 | —- | C] (Microsoft Corp.) – C:\Windows\System32\DfrgNtfs.exe
[2009/08/16 10:05:19 | 00,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\raserver.exe
[2009/08/16 10:05:19 | 00,159,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2009/08/16 10:05:19 | 00,159,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dinput8.dll
[2009/08/16 10:05:19 | 00,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dbnetlib.dll
[2009/08/16 10:05:19 | 00,134,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpdd.dll
[2009/08/16 10:05:19 | 00,121,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dispdiag.exe
[2009/08/16 10:05:19 | 00,097,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cryptnet.dll
[2009/08/16 10:05:19 | 00,096,768 | —- | C] (Microsoft Corp.) – C:\Windows\System32\dfrgfat.exe
[2009/08/16 10:05:19 | 00,094,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\diantz.exe
[2009/08/16 10:05:19 | 00,076,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\rasl2tp.sys
[2009/08/16 10:05:19 | 00,071,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasman.dll
[2009/08/16 10:05:19 | 00,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasqec.dll
[2009/08/16 10:05:19 | 00,068,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DFDWiz.exe
[2009/08/16 10:05:19 | 00,066,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DHCPQEC.DLL
[2009/08/16 10:05:19 | 00,064,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\devenum.dll
[2009/08/16 10:05:19 | 00,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\raspptp.sys
[2009/08/16 10:05:19 | 00,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dhcpsapi.dll
[2009/08/16 10:05:19 | 00,058,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dfrgifc.exe
[2009/08/16 10:05:19 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cryptdll.dll
[2009/08/16 10:05:19 | 00,053,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DfsShlEx.dll
[2009/08/16 10:05:19 | 00,053,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dxof.dll
[2009/08/16 10:05:19 | 00,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2009/08/16 10:05:19 | 00,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dfdts.dll
[2009/08/16 10:05:19 | 00,039,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rasphone.exe
[2009/08/16 10:05:19 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dispci.dll
[2009/08/16 10:05:19 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dimsjob.dll
[2009/08/16 10:05:19 | 00,032,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dispex.dll
[2009/08/16 10:05:19 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmcfg32.dll
[2009/08/16 10:05:19 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\credssp.dll
[2009/08/16 10:05:19 | 00,014,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\CmBatt.sys
[2009/08/16 10:05:19 | 00,008,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpcfgex.dll
[2009/08/16 10:05:19 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\RDPCDD.sys
[2009/08/16 10:05:19 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrss.exe
[2009/08/16 10:05:18 | 01,291,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\comres.dll
[2009/08/16 10:05:18 | 00,686,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\colorui.dll
[2009/08/16 10:05:18 | 00,531,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\comctl32.dll
[2009/08/16 10:05:18 | 00,523,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\clbcatq.dll
[2009/08/16 10:05:18 | 00,297,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmipnpinstall.dll
[2009/08/16 10:05:18 | 00,282,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CompatUI.dll
[2009/08/16 10:05:18 | 00,276,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\compstui.dll
[2009/08/16 10:05:18 | 00,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\comsnap.dll
[2009/08/16 10:05:18 | 00,179,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\els.dll
[2009/08/16 10:05:18 | 00,171,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cic.dll
[2009/08/16 10:05:18 | 00,161,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\COLORCNV.DLL
[2009/08/16 10:05:18 | 00,145,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CompMgmtLauncher.exe
[2009/08/16 10:05:18 | 00,093,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\esentutl.exe
[2009/08/16 10:05:18 | 00,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\comrepl.dll
[2009/08/16 10:05:18 | 00,084,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmstp.exe
[2009/08/16 10:05:18 | 00,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\consent.exe
[2009/08/16 10:05:18 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmdl32.exe
[2009/08/16 10:05:18 | 00,067,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmifw.dll
[2009/08/16 10:05:18 | 00,064,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmicryptinstall.dll
[2009/08/16 10:05:18 | 00,062,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\colbact.dll
[2009/08/16 10:05:18 | 00,056,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\clfsw32.dll
[2009/08/16 10:05:18 | 00,047,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmutil.dll
[2009/08/16 10:05:18 | 00,036,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\esentprf.dll
[2009/08/16 10:05:18 | 00,036,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ComputerDefaults.exe
[2009/08/16 10:05:18 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\circlass.sys
[2009/08/16 10:05:18 | 00,032,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmlua.dll
[2009/08/16 10:05:18 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cofiredm.dll
[2009/08/16 10:05:18 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmpbk32.dll
[2009/08/16 10:05:18 | 00,020,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\compbatt.sys
[2009/08/16 10:05:18 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\convert.exe
[2009/08/16 10:05:18 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmstplua.dll
[2009/08/16 10:05:17 | 02,585,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FirewallControlPanel.exe
[2009/08/16 10:05:17 | 02,249,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Firewall.cpl
[2009/08/16 10:05:17 | 00,616,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dsuiext.dll
[2009/08/16 10:05:17 | 00,442,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\filemgmt.dll
[2009/08/16 10:05:17 | 00,403,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FirewallAPI.dll
[2009/08/16 10:05:17 | 00,394,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dsquery.dll
[2009/08/16 10:05:17 | 00,388,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dmdlgs.dll
[2009/08/16 10:05:17 | 00,376,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpnet.dll
[2009/08/16 10:05:17 | 00,258,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpx.dll
[2009/08/16 10:05:17 | 00,252,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxdiag.exe
[2009/08/16 10:05:17 | 00,235,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dot3gpui.dll
[2009/08/16 10:05:17 | 00,195,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxdiagn.dll
[2009/08/16 10:05:17 | 00,190,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dskquoui.dll
[2009/08/16 10:05:17 | 00,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dmdskmgr.dll
[2009/08/16 10:05:17 | 00,183,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\duser.dll
[2009/08/16 10:05:17 | 00,178,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dmime.dll
[2009/08/16 10:05:17 | 00,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dsdmo.dll
[2009/08/16 10:05:17 | 00,171,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2009/08/16 10:05:17 | 00,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDump.dll
[2009/08/16 10:05:17 | 00,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DpiScaling.exe
[2009/08/16 10:05:17 | 00,155,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dssenh.dll
[2009/08/16 10:05:17 | 00,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dot3ui.dll
[2009/08/16 10:05:17 | 00,134,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dps.dll
[2009/08/16 10:05:17 | 00,131,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dmvdsitf.dll
[2009/08/16 10:05:17 | 00,131,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fde.dll
[2009/08/16 10:05:17 | 00,130,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\drmk.sys
[2009/08/16 10:05:17 | 00,104,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWWIN.EXE
[2009/08/16 10:05:17 | 00,088,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dmview.ocx
[2009/08/16 10:05:17 | 00,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\efsadu.dll
[2009/08/16 10:05:17 | 00,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dskquota.dll
[2009/08/16 10:05:17 | 00,084,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dmscript.dll
[2009/08/16 10:05:17 | 00,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dwmredir.dll
[2009/08/16 10:05:17 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2009/08/16 10:05:17 | 00,067,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EAPQEC.DLL
[2009/08/16 10:05:17 | 00,066,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\driverquery.exe
[2009/08/16 10:05:17 | 00,064,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\findnetprinters.dll
[2009/08/16 10:05:17 | 00,064,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxva2.dll
[2009/08/16 10:05:17 | 00,058,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\fileinfo.sys
[2009/08/16 10:05:17 | 00,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eapsvc.dll
[2009/08/16 10:05:17 | 00,056,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\dumpfve.sys
[2009/08/16 10:05:17 | 00,053,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\extrac32.exe
[2009/08/16 10:05:17 | 00,052,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\expand.exe
[2009/08/16 10:05:17 | 00,051,712 | —- | C] (Microsoft) – C:\Windows\System32\esrb.rs
[2009/08/16 10:05:17 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnshc.dll
[2009/08/16 10:05:17 | 00,045,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dot3dlg.dll
[2009/08/16 10:05:17 | 00,045,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dot3api.dll
[2009/08/16 10:05:17 | 00,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dssec.dll
[2009/08/16 10:05:17 | 00,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dot3gpclnt.dll
[2009/08/16 10:05:17 | 00,042,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dmocx.dll
[2009/08/16 10:05:17 | 00,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eappprxy.dll
[2009/08/16 10:05:17 | 00,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dwmapi.dll
[2009/08/16 10:05:17 | 00,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dmloader.dll
[2009/08/16 10:05:17 | 00,029,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dsauth.dll
[2009/08/16 10:05:17 | 00,027,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\filetrace.sys
[2009/08/16 10:05:17 | 00,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnscacheugc.exe
[2009/08/16 10:05:17 | 00,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fmifs.dll
[2009/08/16 10:05:17 | 00,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\eventcls.dll
[2009/08/16 10:05:17 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dmutil.dll
[2009/08/16 10:05:17 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fdPHost.dll
[2009/08/16 10:05:17 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\dxapi.sys
[2009/08/16 10:05:17 | 00,005,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\drmkaud.sys
[2009/08/16 10:05:17 | 00,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dmdskres2.dll
[2009/08/16 10:05:16 | 04,595,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AuthFWSnapin.dll
[2009/08/16 10:05:16 | 01,370,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Aurora.scr
[2009/08/16 10:05:16 | 00,509,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AuthFWGP.dll
[2009/08/16 10:05:16 | 00,397,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AudioEng.dll
[2009/08/16 10:05:16 | 00,334,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bcdedit.exe
[2009/08/16 10:05:16 | 00,274,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AUDIOKSE.dll
[2009/08/16 10:05:16 | 00,251,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\authfwcfg.dll
[2009/08/16 10:05:16 | 00,244,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\audiodev.dll
[2009/08/16 10:05:16 | 00,192,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bitsadmin.exe
[2009/08/16 10:05:16 | 00,117,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bcdsrv.dll
[2009/08/16 10:05:16 | 00,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AuxiliaryDisplayApi.dll
[2009/08/16 10:05:16 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\atl.dll
[2009/08/16 10:05:16 | 00,068,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\basesrv.dll
[2009/08/16 10:05:16 | 00,058,880 | —- | C] (Microsoft Corporation) – C:\Windows\bfsvc.exe
[2009/08/16 10:05:16 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bcdprov.dll
[2009/08/16 10:05:16 | 00,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\auditpol.exe
[2009/08/16 10:05:16 | 00,028,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\battc.sys
[2009/08/16 10:05:16 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AtBroker.exe
[2009/08/16 10:05:16 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\at.exe
[2009/08/16 10:05:16 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\asyncmac.sys
[2009/08/16 10:05:16 | 00,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\batt.dll
[2009/08/16 10:05:16 | 00,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\bdasup.sys
[2009/08/16 10:05:16 | 00,006,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\beep.sys
[2009/08/16 10:05:15 | 00,317,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\azroleui.dll
[2009/08/16 10:05:15 | 00,091,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\avifil32.dll
[2009/08/16 10:05:15 | 00,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ACW.exe
[2009/08/16 10:05:15 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\AzSqlExt.dll
[2009/08/16 10:05:15 | 00,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\avrt.dll
[2009/08/16 10:05:13 | 01,405,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ActiveContentWizard.dll
[2009/08/16 10:05:13 | 00,326,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\actxprxy.dll
[2009/08/16 10:05:13 | 00,204,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\activeds.dll
[2009/08/16 10:05:13 | 00,167,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ActionQueue.dll
[2009/08/16 10:05:13 | 00,111,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\activeds.tlb
[2009/08/16 10:05:12 | 00,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\apircl.dll
[2009/08/16 10:05:12 | 00,127,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\aclui.dll
[2009/08/16 10:05:12 | 00,070,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\amstream.dll
[2009/08/16 10:05:12 | 00,053,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\1394bus.sys
[2009/08/16 10:05:12 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\amxread.dll
[2009/08/16 10:05:12 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\apilogen.dll
[2009/08/16 10:05:11 | 00,879,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Bubbles.scr
[2009/08/16 10:05:11 | 00,487,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\catsrvut.dll
[2009/08/16 10:05:11 | 00,451,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\catsrv.dll
[2009/08/16 10:05:11 | 00,339,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\appmgr.dll
[2009/08/16 10:05:11 | 00,257,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\adsnt.dll
[2009/08/16 10:05:11 | 00,198,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\apss.dll
[2009/08/16 10:05:11 | 00,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\adsldp.dll
[2009/08/16 10:05:11 | 00,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cabview.dll
[2009/08/16 10:05:11 | 00,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\btpanui.dll
[2009/08/16 10:05:11 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cabinet.dll
[2009/08/16 10:05:11 | 00,059,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\alg.exe
[2009/08/16 10:05:11 | 00,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\appinfo.dll
[2009/08/16 10:05:10 | 00,092,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\bthpan.sys
[2009/08/16 10:05:10 | 00,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\browser.dll
[2009/08/16 10:05:10 | 00,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\bowser.sys
[2009/08/16 10:05:10 | 00,052,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\brcplsdw.dll
[2009/08/16 10:05:10 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cacls.exe
[2009/08/16 10:05:10 | 00,024,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\BOOTVID.DLL
[2009/08/16 10:05:10 | 00,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\capisp.dll
[2009/08/16 10:05:10 | 00,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bridgeunattend.exe
[2009/08/16 10:05:10 | 00,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CertEnrollCtrl.exe
[2009/08/16 10:05:10 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bootstr.dll
[2009/08/16 10:05:09 | 00,805,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdosys.dll
[2009/08/16 10:05:09 | 00,225,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cewmdm.dll
[2009/08/16 10:05:09 | 00,070,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\cdfs.sys
[2009/08/16 10:05:09 | 00,047,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cfgbkend.dll
[2009/08/16 10:05:09 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cfgmgr32.dll
[2009/08/16 10:05:08 | 00,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\bootcfg.exe
[2009/08/16 10:05:08 | 00,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\BlbEvents.dll
[2009/08/16 10:05:08 | 00,022,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\blb_ps.dll
[2009/08/16 10:05:04 | 00,705,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imagesp1.dll
[2009/08/16 10:05:04 | 00,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imagehlp.dll
[2009/08/16 10:05:03 | 00,052,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetmib1.dll
[2009/08/16 10:05:03 | 00,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\InfDefaultInstall.exe
[2009/08/16 10:05:02 | 00,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\i8042prt.sys
[2009/08/16 10:05:02 | 00,018,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ias.dll
[2009/08/16 10:05:02 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iashost.exe
[2009/08/16 10:05:02 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icaapi.dll
[2009/08/16 10:05:01 | 00,123,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ifsutil.dll
[2009/08/16 10:05:01 | 00,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\httpapi.dll
[2009/08/16 10:05:00 | 00,705,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FXSCOMPOSE.dll
[2009/08/16 10:05:00 | 00,473,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FXSCOMEX.dll
[2009/08/16 10:05:00 | 00,289,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\hnetcfg.dll
[2009/08/16 10:05:00 | 00,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icm32.dll
[2009/08/16 10:05:00 | 00,190,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FXSCOVER.exe
[2009/08/16 10:05:00 | 00,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icsfiltr.dll
[2009/08/16 10:05:00 | 00,087,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icfupgd.dll
[2009/08/16 10:05:00 | 00,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\hlink.dll
[2009/08/16 10:05:00 | 00,040,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FXSEXT32.dll
[2009/08/16 10:05:00 | 00,039,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FXSMON.dll
[2009/08/16 10:05:00 | 00,027,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icacls.exe
[2009/08/16 10:05:00 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\idndl.dll
[2009/08/16 10:05:00 | 00,021,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\HotStartUserAgent.dll
[2009/08/16 10:05:00 | 00,014,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\hnetmon.dll
[2009/08/16 10:05:00 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icsunattend.exe
[2009/08/16 10:04:59 | 04,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2009/08/16 10:04:59 | 00,925,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FXSRESM.dll
[2009/08/16 10:04:59 | 00,890,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FXSST.dll
[2009/08/16 10:04:59 | 00,523,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\hhctrl.ocx
[2009/08/16 10:04:59 | 00,523,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FXSSVC.exe
[2009/08/16 10:04:59 | 00,498,176 | —- | C] (Microsoft Corporation) – C:\Windows\HelpPane.exe
[2009/08/16 10:04:59 | 00,456,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FXSXP32.dll
[2009/08/16 10:04:59 | 00,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FXSTIFF.dll
[2009/08/16 10:04:59 | 00,227,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FXSAPI.dll
[2009/08/16 10:04:59 | 00,216,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FXST30.dll
[2009/08/16 10:04:59 | 00,206,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FXSUTILITY.dll
[2009/08/16 10:04:59 | 00,204,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\framedynos.dll
[2009/08/16 10:04:59 | 00,202,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\framedyn.dll
[2009/08/16 10:04:59 | 00,147,439 | —- | C] () – C:\Windows\System32\gpedit.msc
[2009/08/16 10:04:59 | 00,144,909 | —- | C] () – C:\Windows\System32\fsmgmt.msc
[2009/08/16 10:04:59 | 00,110,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fveRecover.dll
[2009/08/16 10:04:59 | 00,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FXSCOM.dll
[2009/08/16 10:04:59 | 00,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\GuidedHelp.dll
[2009/08/16 10:04:59 | 00,067,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FXSROUTE.dll
[2009/08/16 10:04:59 | 00,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\HelpPaneProxy.dll
[2009/08/16 10:04:59 | 00,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\getmac.exe
[2009/08/16 10:04:59 | 00,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\graftabl.com
[2009/08/16 10:04:59 | 00,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fsutil.exe
[2009/08/16 10:04:59 | 00,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fwcfg.dll
[2009/08/16 10:04:59 | 00,050,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fphc.dll
[2009/08/16 10:04:59 | 00,050,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\gacinstall.dll
[2009/08/16 10:04:59 | 00,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fvenotify.exe
[2009/08/16 10:04:59 | 00,045,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\g711codc.ax
[2009/08/16 10:04:59 | 00,025,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\hidparse.sys
[2009/08/16 10:04:59 | 00,021,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\hidir.sys
[2009/08/16 10:04:59 | 00,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\FXSUNATD.exe
[2009/08/16 10:04:59 | 00,016,896 | —- | C] (Microsoft) – C:\Windows\System32\grb.rs
[2009/08/16 10:04:59 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\hcrstco.dll
[2009/08/16 10:04:59 | 00,015,181 | —- | C] () – C:\Windows\System32\gatherWirelessInfo.vbs
[2009/08/16 10:04:59 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\fveupdate.exe
[2009/08/16 10:04:59 | 00,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\fs_rec.sys
[2009/08/16 10:04:59 | 00,012,198 | —- | C] () – C:\Windows\System32\gatherWiredInfo.vbs
[2009/08/16 10:04:59 | 00,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\framebuf.dll
[2009/08/16 10:04:58 | 00,443,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wiashext.dll
[2009/08/16 10:04:58 | 00,415,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wiadefui.dll
[2009/08/16 10:04:58 | 00,171,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wintrust.dll
[2009/08/16 10:04:58 | 00,140,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsta.dll
[2009/08/16 10:04:58 | 00,112,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wiadss.dll
[2009/08/16 10:04:58 | 00,088,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wiascanprofiles.dll
[2009/08/16 10:04:58 | 00,088,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wiaacmgr.exe
[2009/08/16 10:04:58 | 00,076,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtfwd.dll
[2009/08/16 10:04:58 | 00,032,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wiarpc.dll
[2009/08/16 10:04:58 | 00,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wfapigp.dll
[2009/08/16 10:04:58 | 00,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WINSRPC.DLL
[2009/08/16 10:04:57 | 00,628,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WLanConn.dll
[2009/08/16 10:04:57 | 00,383,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinSATAPI.dll
[2009/08/16 10:04:57 | 00,357,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wbemcomn.dll
[2009/08/16 10:04:57 | 00,222,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wavemsp.dll
[2009/08/16 10:04:57 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrsmgr.dll
[2009/08/16 10:04:57 | 00,195,122 | —- | C] () – C:\Windows\System32\winrm.vbs
[2009/08/16 10:04:57 | 00,194,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wbadmin.exe
[2009/08/16 10:04:57 | 00,175,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrscmd.dll
[2009/08/16 10:04:57 | 00,163,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecutil.exe
[2009/08/16 10:04:57 | 00,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wkssvc.dll
[2009/08/16 10:04:57 | 00,145,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecsvc.dll
[2009/08/16 10:04:57 | 00,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wininit.exe
[2009/08/16 10:04:57 | 00,093,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vssadmin.exe
[2009/08/16 10:04:57 | 00,092,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlancfg.dll
[2009/08/16 10:04:57 | 00,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vsstrace.dll
[2009/08/16 10:04:57 | 00,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\w32tm.exe
[2009/08/16 10:04:57 | 00,064,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanapi.dll
[2009/08/16 10:04:57 | 00,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wercplsupport.dll
[2009/08/16 10:04:57 | 00,062,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winethc.dll
[2009/08/16 10:04:57 | 00,062,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\wanarp.sys
[2009/08/16 10:04:57 | 00,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winipsec.dll
[2009/08/16 10:04:57 | 00,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wermgr.exe
[2009/08/16 10:04:57 | 00,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecapi.dll
[2009/08/16 10:04:57 | 00,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WavDest.dll
[2009/08/16 10:04:57 | 00,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\waitfor.exe
[2009/08/16 10:04:57 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrs.exe
[2009/08/16 10:04:57 | 00,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\werdiagcontroller.dll
[2009/08/16 10:04:57 | 00,027,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WinFax.dll
[2009/08/16 10:04:57 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vss_ps.dll
[2009/08/16 10:04:57 | 00,022,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrshost.exe
[2009/08/16 10:04:57 | 00,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winusb.dll
[2009/08/16 10:04:57 | 00,014,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winnsi.dll
[2009/08/16 10:04:57 | 00,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wertargets.wtl
[2009/08/16 10:04:56 | 02,537,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpdshext.dll
[2009/08/16 10:04:56 | 01,675,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xpssvcs.dll
[2009/08/16 10:04:56 | 01,295,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsecedit.dll
[2009/08/16 10:04:56 | 00,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpd_ci.dll
[2009/08/16 10:04:56 | 00,574,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XPSSHHDR.dll
[2009/08/16 10:04:56 | 00,503,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\Wdf01000.sys
[2009/08/16 10:04:56 | 00,456,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wvc.dll
[2009/08/16 10:04:56 | 00,349,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WPDSp.dll
[2009/08/16 10:04:56 | 00,305,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFx.dll
[2009/08/16 10:04:56 | 00,296,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Wpc.dll
[2009/08/16 10:04:56 | 00,296,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xwizards.dll
[2009/08/16 10:04:56 | 00,203,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpdwcn.dll
[2009/08/16 10:04:56 | 00,192,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsqmcons.exe
[2009/08/16 10:04:56 | 00,188,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSManMigrationPlugin.dll
[2009/08/16 10:04:56 | 00,183,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xmllite.dll
[2009/08/16 10:04:56 | 00,181,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFPlatform.dll
[2009/08/16 10:04:56 | 00,179,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ws2_32.dll
[2009/08/16 10:04:56 | 00,175,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmWmiPl.dll
[2009/08/16 10:04:56 | 00,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSTPager.ax
[2009/08/16 10:04:56 | 00,168,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wdigest.dll
[2009/08/16 10:04:56 | 00,154,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmidx.dll
[2009/08/16 10:04:56 | 00,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuwebv.dll
[2009/08/16 10:04:56 | 00,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFHost.exe
[2009/08/16 10:04:56 | 00,131,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WPDShServiceObj.dll
[2009/08/16 10:04:56 | 00,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmAuto.dll
[2009/08/16 10:04:56 | 00,095,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactsrv.dll
[2009/08/16 10:04:56 | 00,087,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFCoinstaller.dll
[2009/08/16 10:04:56 | 00,083,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\WUDFRd.sys
[2009/08/16 10:04:56 | 00,080,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wudriver.dll
[2009/08/16 10:04:56 | 00,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wdi.dll
[2009/08/16 10:04:56 | 00,072,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpclsp.dll
[2009/08/16 10:04:56 | 00,070,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wzcdlg.dll
[2009/08/16 10:04:56 | 00,070,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpdbusenum.dll
[2009/08/16 10:04:56 | 00,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscmisetup.dll
[2009/08/16 10:04:56 | 00,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFSvc.dll
[2009/08/16 10:04:56 | 00,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmProv.dll
[2009/08/16 10:04:56 | 00,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\WUDFPf.sys
[2009/08/16 10:04:56 | 00,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuauclt.exe
[2009/08/16 10:04:56 | 00,039,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wpnpinst.exe
[2009/08/16 10:04:56 | 00,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xolehlp.dll
[2009/08/16 10:04:56 | 00,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xcopy.exe
[2009/08/16 10:04:56 | 00,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wshcon.dll
[2009/08/16 10:04:56 | 00,035,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\WdfLdr.sys
[2009/08/16 10:04:56 | 00,032,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups2.dll
[2009/08/16 10:04:56 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wuapp.exe
[2009/08/16 10:04:56 | 00,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSManHTTPConfig.exe
[2009/08/16 10:04:56 | 00,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WPDShextAutoplay.exe
[2009/08/16 10:04:56 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wtsapi32.dll
[2009/08/16 10:04:56 | 00,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wups.dll
[2009/08/16 10:04:56 | 00,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xmlprovi.dll
[2009/08/16 10:04:56 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ws2ifsl.sys
[2009/08/16 10:04:56 | 00,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsock32.dll
[2009/08/16 10:04:56 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmRes.dll
[2009/08/16 10:04:56 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\wmiacpi.sys
[2009/08/16 10:04:56 | 00,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wscproxystub.dll
[2009/08/16 10:04:56 | 00,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSHTCPIP.DLL
[2009/08/16 10:04:56 | 00,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wship6.dll
[2009/08/16 10:04:56 | 00,001,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmCl.dll
[2009/08/16 10:04:55 | 01,642,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPEncEn.dll
[2009/08/16 10:04:55 | 01,548,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVDECOD.DLL
[2009/08/16 10:04:55 | 01,329,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMSPDMOE.DLL
[2009/08/16 10:04:55 | 01,118,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMADMOE.DLL
[2009/08/16 10:04:55 | 00,913,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WlanMM.dll
[2009/08/16 10:04:55 | 00,767,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVSENCD.DLL
[2009/08/16 10:04:55 | 00,758,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMADMOD.DLL
[2009/08/16 10:04:55 | 00,604,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMSPDMOD.DLL
[2009/08/16 10:04:55 | 00,498,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlandlg.dll
[2009/08/16 10:04:55 | 00,418,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmdrmdev.dll
[2009/08/16 10:04:55 | 00,347,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmdrmnet.dll
[2009/08/16 10:04:55 | 00,310,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpdxm.dll
[2009/08/16 10:04:55 | 00,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlansec.dll
[2009/08/16 10:04:55 | 00,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMASF.DLL
[2009/08/16 10:04:55 | 00,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpsrcwp.dll
[2009/08/16 10:04:55 | 00,153,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmvdspa.dll
[2009/08/16 10:04:55 | 00,120,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WLanHC.dll
[2009/08/16 10:04:55 | 00,101,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpshell.dll
[2009/08/16 10:04:55 | 00,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanext.exe
[2009/08/16 10:04:55 | 00,041,472 | —- | C] (Microsoft) – C:\Windows\System32\WlanMmHC.dll
[2009/08/16 10:04:55 | 00,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmiprop.dll
[2009/08/16 10:04:55 | 00,022,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpcm.dll
[2009/08/16 10:04:55 | 00,017,976 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\wmilib.sys
[2009/08/16 10:04:54 | 00,691,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TabletPC.cpl
[2009/08/16 10:04:54 | 00,431,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tdh.dll
[2009/08/16 10:04:54 | 00,357,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskschd.dll
[2009/08/16 10:04:54 | 00,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskmgr.exe
[2009/08/16 10:04:54 | 00,155,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2009/08/16 10:04:54 | 00,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TapiMigPlugin.dll
[2009/08/16 10:04:54 | 00,094,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Tabbtn.dll
[2009/08/16 10:04:54 | 00,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tasklist.exe
[2009/08/16 10:04:54 | 00,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskkill.exe
[2009/08/16 10:04:54 | 00,076,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\systeminfo.exe
[2009/08/16 10:04:54 | 00,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tabcal.exe
[2009/08/16 10:04:54 | 00,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tbssvc.dll
[2009/08/16 10:04:54 | 00,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TabbtnEx.dll
[2009/08/16 10:04:54 | 00,029,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\tdtcp.sys
[2009/08/16 10:04:54 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\tape.sys
[2009/08/16 10:04:54 | 00,020,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\tdi.sys
[2009/08/16 10:04:54 | 00,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\tdpipe.sys
[2009/08/16 10:04:54 | 00,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tbs.dll
[2009/08/16 10:04:53 | 08,322,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwizimg.dll
[2009/08/16 10:04:53 | 08,139,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ssBranded.scr
[2009/08/16 10:04:53 | 00,604,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sqlceqp30.dll
[2009/08/16 10:04:53 | 00,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sxs.dll
[2009/08/16 10:04:53 | 00,348,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwizeng.dll
[2009/08/16 10:04:53 | 00,338,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SysFxUI.dll
[2009/08/16 10:04:53 | 00,308,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sqlcese30.dll
[2009/08/16 10:04:53 | 00,294,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ssText3d.scr
[2009/08/16 10:04:53 | 00,274,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srrstr.dll
[2009/08/16 10:04:53 | 00,259,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\upnphost.dll
[2009/08/16 10:04:53 | 00,251,904 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sti_ci.dll
[2009/08/16 10:04:53 | 00,242,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sysdm.cpl
[2009/08/16 10:04:53 | 00,195,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\upnp.dll
[2009/08/16 10:04:53 | 00,175,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\syncui.dll
[2009/08/16 10:04:53 | 00,155,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ssdpsrv.dll
[2009/08/16 10:04:53 | 00,134,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbvideo.sys
[2009/08/16 10:04:53 | 00,129,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sqmapi.dll
[2009/08/16 10:04:53 | 00,127,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SoundRecorder.exe
[2009/08/16 10:04:53 | 00,116,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sstpsvc.dll
[2009/08/16 10:04:53 | 00,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SSShim.dll
[2009/08/16 10:04:53 | 00,095,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xwtpw32.dll
[2009/08/16 10:04:53 | 00,083,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\usbui.dll
[2009/08/16 10:04:53 | 00,075,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\synceng.dll
[2009/08/16 10:04:53 | 00,064,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spbcd.dll
[2009/08/16 10:04:53 | 00,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\takeown.exe
[2009/08/16 10:04:53 | 00,047,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\syssetup.dll
[2009/08/16 10:04:53 | 00,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sppnp.dll
[2009/08/16 10:04:53 | 00,040,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srclient.dll
[2009/08/16 10:04:53 | 00,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\usbmon.dll
[2009/08/16 10:04:53 | 00,027,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\syskey.exe
[2009/08/16 10:04:53 | 00,027,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sxstrace.exe
[2009/08/16 10:04:53 | 00,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\userinit.exe
[2009/08/16 10:04:53 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srwmi.dll
[2009/08/16 10:04:53 | 00,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbuhci.sys
[2009/08/16 10:04:53 | 00,022,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\upnpcont.exe
[2009/08/16 10:04:53 | 00,022,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sxsstore.dll
[2009/08/16 10:04:53 | 00,021,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\svchost.exe
[2009/08/16 10:04:53 | 00,021,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\spldr.sys
[2009/08/16 10:04:53 | 00,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spopk.dll
[2009/08/16 10:04:53 | 00,015,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\swenum.sys
[2009/08/16 10:04:53 | 00,014,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\srdelayed.exe
[2009/08/16 10:04:53 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\usbperf.dll
[2009/08/16 10:04:53 | 00,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwizres.dll
[2009/08/16 10:04:53 | 00,005,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbd.sys
[2009/08/16 10:04:52 | 00,246,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\VIDRESZR.DLL
[2009/08/16 10:04:52 | 00,110,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\videoprt.sys
[2009/08/16 10:04:52 | 00,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\usbccgp.sys
[2009/08/16 10:04:52 | 00,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vga256.dll
[2009/08/16 10:04:52 | 00,052,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\volmgr.sys
[2009/08/16 10:04:52 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\vgapnp.sys
[2009/08/16 10:04:52 | 00,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\vga.sys
[2009/08/16 10:04:52 | 00,021,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vga64k.dll
[2009/08/16 10:04:52 | 00,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vga.dll
[2009/08/16 10:04:51 | 00,337,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tracerpt.exe
[2009/08/16 10:04:51 | 00,257,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\VAN.dll
[2009/08/16 10:04:51 | 00,240,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\uxtheme.dll
[2009/08/16 10:04:51 | 00,164,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\VBICodec.ax
[2009/08/16 10:04:51 | 00,157,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\verifier.dll
[2009/08/16 10:04:51 | 00,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vdsbas.dll
[2009/08/16 10:04:51 | 00,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\uudf.dll
[2009/08/16 10:04:51 | 00,112,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\verifier.exe
[2009/08/16 10:04:51 | 00,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\trkwks.dll
[2009/08/16 10:04:51 | 00,056,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vfwwdm32.dll
[2009/08/16 10:04:51 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vdmredir.dll
[2009/08/16 10:04:51 | 00,037,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vds_ps.dll
[2009/08/16 10:04:51 | 00,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbisurf.ax
[2009/08/16 10:04:51 | 00,029,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\utildll.dll
[2009/08/16 10:04:51 | 00,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vdsldr.exe
[2009/08/16 10:04:50 | 02,588,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIHub.dll
[2009/08/16 10:04:50 | 01,298,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TMM.dll
[2009/08/16 10:04:50 | 00,736,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\unbcl.dll
[2009/08/16 10:04:50 | 00,355,328 | —- | C] (Microsoft Corporation) – C:\Windows\System32\termmgr.dll
[2009/08/16 10:04:50 | 00,310,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\unregmp2.exe
[2009/08/16 10:04:50 | 00,201,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\unattend.dll
[2009/08/16 10:04:50 | 00,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAutomationCore.dll
[2009/08/16 10:04:50 | 00,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\twext.dll
[2009/08/16 10:04:50 | 00,092,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ufat.dll
[2009/08/16 10:04:50 | 00,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\txflog.dll
[2009/08/16 10:04:50 | 00,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TpmInit.exe
[2009/08/16 10:04:50 | 00,080,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\thumbcache.dll
[2009/08/16 10:04:50 | 00,062,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TSpkg.dll
[2009/08/16 10:04:50 | 00,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\uexfat.dll
[2009/08/16 10:04:50 | 00,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\System32\umb.dll
[2009/08/16 10:04:50 | 00,045,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ucsvc.exe
[2009/08/16 10:04:50 | 00,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\TimeDateMUICallback.dll
[2009/08/16 10:04:50 | 00,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UI0Detect.exe
[2009/08/16 10:04:50 | 00,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\umbus.sys
[2009/08/16 10:04:50 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\unlodctr.exe
[2009/08/16 10:04:50 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\unattendedjoin.exe
[2009/08/16 10:04:50 | 00,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\tssecsrv.sys
[2009/08/16 10:04:50 | 00,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\tunnel.sys
[2009/08/16 10:04:50 | 00,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\TUNMP.SYS
[2009/08/16 10:04:50 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tsddd.dll
[2009/08/16 10:04:50 | 00,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\txfw32.dll
[2009/08/16 10:04:50 | 00,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\umpass.sys
[2009/08/16 10:03:18 | 00,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\kbd106n.dll
[2009/08/16 10:02:12 | 00,196,608 | —- | C] () – C:\Windows\SPInstall.etl
[2009/08/16 09:42:05 | 00,106,496 | —- | C] () – C:\Users\o0 Virgo 0o\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/08/16 09:41:46 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Roaming\Identities
[2009/08/16 09:41:44 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Local\VirtualStore
[2009/08/16 09:41:42 | 00,000,680 | —- | C] () – C:\Users\o0 Virgo 0o\AppData\Local\d3d9caps.dat
[2009/08/16 09:41:41 | 00,000,000 | –SD | C] – C:\Users\o0 Virgo 0o\AppData\Roaming\Microsoft
[2009/08/16 09:41:41 | 00,000,000 | -HSD | C] – C:\Users\o0 Virgo 0o\Documents\My Videos
[2009/08/16 09:41:41 | 00,000,000 | -HSD | C] – C:\Users\o0 Virgo 0o\Documents\My Pictures
[2009/08/16 09:41:41 | 00,000,000 | -HSD | C] – C:\Users\o0 Virgo 0o\Documents\My Music
[2009/08/16 09:41:41 | 00,000,000 | -HSD | C] – C:\Users\o0 Virgo 0o\AppData\Local\Temporary Internet Files
[2009/08/16 09:41:41 | 00,000,000 | -HSD | C] – C:\Users\o0 Virgo 0o\AppData\Local\History
[2009/08/16 09:41:41 | 00,000,000 | -HSD | C] – C:\Users\o0 Virgo 0o\AppData\Local\Application Data
[2009/08/16 09:41:41 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Roaming\Media Center Programs
[2009/08/16 09:41:41 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Local\Temp
[2009/08/16 09:41:41 | 00,000,000 | —D | C] – C:\Users\o0 Virgo 0o\AppData\Local\Microsoft
[2009/08/16 09:32:53 | 00,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2009/08/16 09:31:35 | 00,000,000 | —D | C] – C:\Windows\Debug
[2009/08/16 09:31:34 | 00,000,000 | —D | C] – C:\Windows\CSC
[2009/08/16 09:26:38 | 00,000,000 | —D | C] – C:\Windows\Prefetch
[2008/10/28 13:39:14 | 01,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2007/11/15 06:17:34 | 00,204,800 | —- | C] () – C:\Windows\System32\CogentBioSDK.dll
[2006/11/02 19:34:20 | 00,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 17:23:31 | 00,000,219 | —- | C] () – C:\Windows\win.ini
[2006/11/02 17:23:31 | 00,000,219 | —- | C] () – C:\Windows\system.ini
[2006/11/02 14:40:29 | 00,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2001/11/15 02:56:00 | 01,802,240 | —- | C] () – C:\Windows\System32\lcppn21.dll

========== Files - Modified Within 30 Days ==========

[2009/08/26 08:25:52 | 00,514,048 | —- | M] (OldTimer Tools) – C:\Users\o0 Virgo 0o\Desktop\OTL.exe
[2009/08/26 08:21:11 | 00,000,000 | —- | M] () – C:\Users\o0 Virgo 0o\Desktop\settings.dat
[2009/08/26 08:20:38 | 00,280,282 | —- | M] () – C:\Users\o0 Virgo 0o\Desktop\gmer.zip
[2009/08/26 07:36:24 | 00,028,409 | —- | M] () – C:\ProgramData\nvModes.001
[2009/08/26 07:22:35 | 00,690,960 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2009/08/26 07:22:35 | 00,595,684 | —- | M] () – C:\Windows\System32\perfh009.dat
[2009/08/26 07:22:35 | 00,101,350 | —- | M] () – C:\Windows\System32\perfc009.dat
[2009/08/26 07:17:43 | 00,000,281 | —- | M] () – C:\Users\Public\Documents\hpqp.ini
[2009/08/26 07:16:29 | 00,004,432 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/08/26 07:16:28 | 00,004,432 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/08/26 07:16:14 | 00,028,409 | —- | M] () – C:\ProgramData\nvModes.dat
[2009/08/26 07:16:01 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/08/26 07:15:54 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/08/26 07:15:46 | 32,182,96832 | -HS- | M] () – C:\hiberfil.sys
[2009/08/26 07:14:38 | 01,674,053 | -H– | M] () – C:\Users\o0 Virgo 0o\AppData\Local\IconCache.db
[2009/08/26 04:05:06 | 00,318,976 | —- | M] (Microsoft Corporation) – C:\Windows\System32\CF31806.exe
[2009/08/26 04:03:34 | 00,318,976 | —- | M] (Microsoft Corporation) – C:\Windows\System32\CF31506.exe
[2009/08/26 03:57:30 | 00,318,976 | —- | M] (Microsoft Corporation) – C:\Windows\System32\CF30317.exe
[2009/08/26 03:44:45 | 03,184,487 | R— | M] () – C:\Users\o0 Virgo 0o\Desktop\ComboFix.exe
[2009/08/25 21:57:48 | 00,318,976 | —- | M] (Microsoft Corporation) – C:\Windows\System32\CF25375.exe
[2009/08/25 21:50:26 | 00,046,080 | —- | M] () – C:\Users\o0 Virgo 0o\Desktop\Win32kDiag.exe
[2009/08/25 19:28:41 | 00,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2009/08/25 19:01:31 | 00,318,976 | —- | M] (Microsoft Corporation) – C:\Windows\System32\CF23603.exe
[2009/08/25 18:54:56 | 00,318,976 | —- | M] (Microsoft Corporation) – C:\Windows\System32\CF22313.exe
[2009/08/25 18:06:33 | 00,318,976 | —- | M] (Microsoft Corporation) – C:\Windows\System32\CF12833.exe
[2009/08/25 10:19:30 | 00,359,932 | —- | M] () – C:\Users\o0 Virgo 0o\Desktop\dds.EXE
[2009/08/24 01:05:53 | 00,006,144 | —- | M] () – C:\Users\o0 Virgo 0o\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/24 01:02:05 | 00,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
[2009/08/23 03:09:13 | 00,229,376 | —- | M] () – C:\Windows\PEV.exe
[2009/08/21 06:37:39 | 00,051,355 | —- | M] () – C:\Windows\System32\muzika.xm
[2009/08/20 18:57:20 | 00,000,074 | —- | M] () – C:\autoexec.bat
[2009/08/20 18:44:50 | 00,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_SynTP_01000.Wdf
[2009/08/20 18:41:58 | 00,000,251 | —- | M] () – C:\Windows\xUninstall.bat
[2009/08/20 18:27:42 | 00,000,680 | —- | M] () – C:\Users\o0 Virgo 0o\AppData\Local\d3d9caps.dat
[2009/08/20 16:37:59 | 00,106,496 | —- | M] () – C:\Users\o0 Virgo 0o\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/08/20 16:36:55 | 02,311,808 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2009/08/20 06:50:40 | 00,000,219 | —- | M] () – C:\Windows\win.ini
[2009/08/20 05:39:19 | 00,000,000 | —- | M] () – C:\Windows\nsreg.dat
[2009/08/16 10:31:08 | 00,000,749 | RH– | M] () – C:\Windows\WindowsShell.Manifest
[2009/08/16 10:18:28 | 00,101,888 | —- | M] (Infineon Technologies AG) – C:\Windows\System32\ifxcardm.dll
[2009/08/16 10:18:28 | 00,052,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mrt.exe
[2009/08/16 10:18:20 | 00,082,432 | —- | M] (Gemalto, Inc.) – C:\Windows\System32\axaltocm.dll
[2009/08/16 10:12:45 | 00,196,608 | —- | M] () – C:\Windows\SPInstall.etl
[2009/08/16 09:33:28 | 00,041,176 | —- | M] () – C:\Windows\System32\license.rtf
[2009/08/13 11:14:18 | 00,472,064 | —- | M] ( ) – C:\Users\o0 Virgo 0o\Desktop\RootRepeal.exe
[2009/08/03 13:36:28 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/08/03 13:36:06 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys

========== LOP Check ==========

[2009/08/22 18:28:25 | 00,000,000 | —D | M] – C:\Users\o0 Virgo 0o\AppData\Roaming
[2009/08/21 01:09:52 | 00,000,000 | —D | M] – C:\Users\o0 Virgo 0o\AppData\Roaming\Desktopicon
[2009/08/20 19:12:10 | 00,000,000 | —D | M] – C:\Users\o0 Virgo 0o\AppData\Roaming\DigitalPersona
[2009/08/26 07:35:59 | 00,000,000 | —D | M] – C:\Users\o0 Virgo 0o\AppData\Roaming\DMCache
[2009/08/21 03:15:56 | 00,000,000 | —D | M] – C:\Users\o0 Virgo 0o\AppData\Roaming\ESET
[2009/08/20 06:04:09 | 00,000,000 | —D | M] – C:\Users\o0 Virgo 0o\AppData\Roaming\Foxit
[2009/08/20 18:42:52 | 00,000,000 | —D | M] – C:\Users\o0 Virgo 0o\AppData\Roaming\Hewlett Packard
[2009/08/20 17:03:12 | 00,000,000 | —D | M] – C:\Users\o0 Virgo 0o\AppData\Roaming\IDM
[2009/08/20 18:52:02 | 00,000,000 | —D | M] – C:\Users\o0 Virgo 0o\AppData\Roaming\Macrovision
[2006/11/02 19:35:50 | 00,000,000 | —D | M] – C:\Users\o0 Virgo 0o\AppData\Roaming\Media Center Programs
[2009/08/26 04:13:32 | 00,000,000 | —D | M] – C:\Users\o0 Virgo 0o\AppData\Roaming\MTD
[2009/08/20 05:37:58 | 00,000,000 | —D | M] – C:\Users\o0 Virgo 0o\AppData\Roaming\URSoft
[2009/08/26 07:16:01 | 00,000,006 | -H– | M] () – C:\Windows\Tasks\SA.DAT
[2009/08/26 07:14:44 | 00,016,290 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 167 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 161 bytes -> C:\ProgramData\TEMP:B3D74A13
< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI